Field notebook · source record
AC-4(15)
Access ControlDetection of Unsanctioned Information
The statement below is source material, not a generated control summary.
Source statement
When transferring information between different security domains, examine the information for the presence of {{ insert: param, ac-04.15_odp.01 }} and prohibit the transfer of such information in accordance with the {{ insert: param, ac-4.15_prm_2 }}.
Guidance
Unsanctioned information includes malicious code, information that is inappropriate for release from the source network, or executable code that could disrupt or harm the services or systems on the destination network.
Organization-defined parameters
Organization-defined · unresolvedCatalog reference only. No project value has been assigned or evaluated here.
- ac-4.15_prm_2
organization-defined security or privacy policy
- ac-04.15_odp.01
unsanctioned information
Source guidance- unsanctioned information to be detected is defined;
- ac-04.15_odp.02
security policy
Source guidance- security policy that requires the transfer of unsanctioned information between different security domains to be prohibited is defined (if selected);
- ac-04.15_odp.03
privacy policy
Source guidance- privacy policy that requires the transfer of organization-defined unsanctioned information between different security domains to be prohibited is defined (if selected);
Assessment reference context
Retained, not activated.1 source assessment records and 3 objective nodes are available as reference context. This surface runs none of them.
ac-4.15_objAC-04(15)3 objective nodes
- when transferring information between different security domains, information is examined for the presence of {{ insert: param, ac-04.15_odp.01 }};
- when transferring information between different security domains, transfer of {{ insert: param, ac-04.15_odp.01 }} is prohibited in accordance with the {{ insert: param, ac-04.15_odp.02 }};
- when transferring information between different security domains, transfer of {{ insert: param, ac-04.15_odp.01 }} is prohibited in accordance with the {{ insert: param, ac-04.15_odp.03 }}.
Reference method and authority
- InputExact release, source digest, control ID, and cited source fields
- Agent taskPrepare a bounded evidence request or test-plan draft
- Fail closedAbstain when source, scope, or assessment identity is missing
- Human acceptanceA named reviewer decides whether evidence supports the conclusion