Field notebook · source record
AC-4(14)
Access ControlSecurity or Privacy Policy Filter Constraints
The statement below is source material, not a generated control summary.
Source statement
When transferring information between different security domains, implement {{ insert: param, ac-4.14_prm_1 }} requiring fully enumerated formats that restrict data structure and content.
Guidance
Data structure and content restrictions reduce the range of potential malicious or unsanctioned content in cross-domain transactions. Security or privacy policy filters that restrict data structures include restricting file sizes and field lengths. Data content policy filters include encoding formats for character sets, restricting character data fields to only contain alpha-numeric characters, prohibiting special characters, and validating schema structures.
Organization-defined parameters
Organization-defined · unresolvedCatalog reference only. No project value has been assigned or evaluated here.
- ac-4.14_prm_1
organization-defined security or privacy policy filters
- ac-04.14_odp.01
security policy filters
Source guidance- security policy filters to be implemented that require fully enumerated formats restricting data structure and content have been defined;
- ac-04.14_odp.02
privacy policy filters
Source guidance- privacy policy filters to be implemented that require fully enumerated formats restricting data structure and content are defined;
Assessment reference context
Retained, not activated.1 source assessment records and 2 objective nodes are available as reference context. This surface runs none of them.
ac-4.14_objAC-04(14)2 objective nodes
- when transferring information between different security domains, implemented {{ insert: param, ac-04.14_odp.01 }} require fully enumerated formats that restrict data structure and content;
- when transferring information between different security domains, implemented {{ insert: param, ac-04.14_odp.02 }} require fully enumerated formats that restrict data structure and content.
Reference method and authority
- InputExact release, source digest, control ID, and cited source fields
- Agent taskPrepare a bounded evidence request or test-plan draft
- Fail closedAbstain when source, scope, or assessment identity is missing
- Human acceptanceA named reviewer decides whether evidence supports the conclusion