Field notebook · source record
AC-4(4)
Access ControlFlow Control of Encrypted Information
The statement below is source material, not a generated control summary.
Source statement
Prevent encrypted information from bypassing {{ insert: param, ac-04.04_odp.01 }} by {{ insert: param, ac-04.04_odp.02 }}.
Guidance
Flow control mechanisms include content checking, security policy filters, and data type identifiers. The term encryption is extended to cover encoded data not recognized by filtering mechanisms.
Organization-defined parameters
Organization-defined · unresolvedCatalog reference only. No project value has been assigned or evaluated here.
- ac-04.04_odp.01
information flow control mechanisms
Source guidance- information flow control mechanisms that encrypted information is prevented from bypassing are defined;
- ac-04.04_odp.02
Organization-defined parameter
Allowed selection · one-or-more- decrypting the information
- blocking the flow of the encrypted information
- terminating communications sessions attempting to pass encrypted information
- {{ insert: param, ac-04.04_odp.03 }}
- ac-04.04_odp.03
organization-defined procedure or method
Source guidance- the organization-defined procedure or method used to prevent encrypted information from bypassing information flow control mechanisms is defined (if selected);
Assessment reference context
Retained, not activated.1 source assessment records and 1 objective nodes are available as reference context. This surface runs none of them.
ac-4.4_objAC-04(04)1 objective nodes
- encrypted information is prevented from bypassing {{ insert: param, ac-04.04_odp.01 }} by {{ insert: param, ac-04.04_odp.02 }}.
Reference method and authority
- InputExact release, source digest, control ID, and cited source fields
- Agent taskPrepare a bounded evidence request or test-plan draft
- Fail closedAbstain when source, scope, or assessment identity is missing
- Human acceptanceA named reviewer decides whether evidence supports the conclusion