Field notebook · source record
AC-4(2)
Access ControlProcessing Domains
The statement below is source material, not a generated control summary.
Source statement
Use protected processing domains to enforce {{ insert: param, ac-04.02_odp }} as a basis for flow control decisions.
Guidance
Protected processing domains within systems are processing spaces that have controlled interactions with other processing spaces, enabling control of information flows between these spaces and to/from information objects. A protected processing domain can be provided, for example, by implementing domain and type enforcement. In domain and type enforcement, system processes are assigned to domains, information is identified by types, and information flows are controlled based on allowed information accesses (i.e., determined by domain and type), allowed signaling among domains, and allowed process transitions to other domains.
Organization-defined parameters
Organization-defined · unresolvedCatalog reference only. No project value has been assigned or evaluated here.
- ac-04.02_odp
information flow control policies
Source guidance- information flow control policies to be enforced by use of protected processing domains are defined;
Assessment reference context
Retained, not activated.1 source assessment records and 1 objective nodes are available as reference context. This surface runs none of them.
ac-4.2_objAC-04(02)1 objective nodes
- protected processing domains are used to enforce {{ insert: param, ac-04.02_odp }} as a basis for flow control decisions.
Reference method and authority
- InputExact release, source digest, control ID, and cited source fields
- Agent taskPrepare a bounded evidence request or test-plan draft
- Fail closedAbstain when source, scope, or assessment identity is missing
- Human acceptanceA named reviewer decides whether evidence supports the conclusion