Field notebook · source record
AC-4(8)
Access ControlSecurity and Privacy Policy Filters
The statement below is source material, not a generated control summary.
Source statement
Enforce information flow control using {{ insert: param, ac-4.8_prm_1 }} as a basis for flow control decisions for {{ insert: param, ac-4.8_prm_2 }} ; and {{ insert: param, ac-04.08_odp.05 }} data after a filter processing failure in accordance with {{ insert: param, ac-4.8_prm_4 }}.
Guidance
Organization-defined security or privacy policy filters can address data structures and content. For example, security or privacy policy filters for data structures can check for maximum file lengths, maximum field sizes, and data/file types (for structured and unstructured data). Security or privacy policy filters for data content can check for specific words, enumerated values or data value ranges, and hidden content. Structured data permits the interpretation of data content by applications. Unstructured data refers to digital information without a data structure or with a data structure that does not facilitate the development of rule sets to address the impact or classification level of the information conveyed by the data or the flow enforcement decisions. Unstructured data consists of bitmap objects that are inherently non-language-based (i.e., image, video, or audio files) and textual objects that are based on written or printed languages. Organizations can implement more than one security or privacy policy filter to meet information flow control objectives.
Organization-defined parameters
Organization-defined · unresolvedCatalog reference only. No project value has been assigned or evaluated here.
- ac-4.8_prm_1
organization-defined security or privacy policy filters
- ac-4.8_prm_2
organization-defined information flows
- ac-4.8_prm_4
organization-defined security or privacy policy
- ac-04.08_odp.01
security policy filter
Source guidance- security policy filters to be used as a basis for enforcing information flow control are defined;
- ac-04.08_odp.02
privacy policy filter
Source guidance- privacy policy filters to be used as a basis for enforcing information flow control are defined;
- ac-04.08_odp.03
information flows
Source guidance- information flows for which information flow control is enforced by security filters are defined;
- ac-04.08_odp.04
information flows
Source guidance- information flows for which information flow control is enforced by privacy filters are defined;
- ac-04.08_odp.05
Organization-defined parameter
Allowed selection · one-or-more- block
- strip
- modify
- quarantine
- ac-04.08_odp.06
security policy
Source guidance- security policy identifying actions to be taken after a filter processing failure are defined;
- ac-04.08_odp.07
privacy policy
Source guidance- privacy policy identifying actions to be taken after a filter processing failure are defined;
Assessment reference context
Retained, not activated.1 source assessment records and 3 objective nodes are available as reference context. This surface runs none of them.
ac-4.8_objAC-04(08)3 objective nodes
- information flow control is enforced using {{ insert: param, ac-04.08_odp.01 }} as a basis for flow control decisions for {{ insert: param, ac-04.08_odp.03 }};
- information flow control is enforced using {{ insert: param, ac-04.08_odp.02 }} as a basis for flow control decisions for {{ insert: param, ac-04.08_odp.04 }};
- {{ insert: param, ac-04.08_odp.05 }} data after a filter processing failure in accordance with {{ insert: param, ac-04.08_odp.06 }}; {{ insert: param, ac-04.08_odp.05 }} data after a filter processing failure in accordance with {{ insert: param, ac-04.08_odp.07 }}.
Reference method and authority
- InputExact release, source digest, control ID, and cited source fields
- Agent taskPrepare a bounded evidence request or test-plan draft
- Fail closedAbstain when source, scope, or assessment identity is missing
- Human acceptanceA named reviewer decides whether evidence supports the conclusion