Skip to main content

πŸ’Ό AC-4 INFORMATION FLOW ENFORCEMENT

  • Contextual name: πŸ’Ό AC-4 INFORMATION FLOW ENFORCEMENT
  • ID: /frameworks/nist-sp-800-53-r4/ac/04
  • Located in: πŸ’Ό AC ACCESS CONTROL

Description​

The information system enforces approved authorizations for controlling the flow of information within the system and between interconnected systems based on [Assignment: organization-defined information flow control policies].

Similar​

  • Internal
    • ID: dec-c-7e6eca71

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό DE.AE-1: A baseline of network operations and expected data flows for users and systems is established and managed1011
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό ID.AM-3: Organizational communication and data flows are mapped33
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό PR.AC-5: Network integrity is protected (e.g., network segregation, network segmentation)713
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό PR.DS-5: Protections against data leaks are implemented4150
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό PR.PT-4: Communications and control networks are protected713

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό AC-4 (1) OBJECT SECURITY ATTRIBUTES
πŸ’Ό AC-4 (2) PROCESSING DOMAINS
πŸ’Ό AC-4 (3) DYNAMIC INFORMATION FLOW CONTROL
πŸ’Ό AC-4 (4) CONTENT CHECK ENCRYPTED INFORMATION
πŸ’Ό AC-4 (5) EMBEDDED DATA TYPES11
πŸ’Ό AC-4 (6) METADATA
πŸ’Ό AC-4 (7) ONE-WAY FLOW MECHANISMS
πŸ’Ό AC-4 (8) SECURITY POLICY FILTERS
πŸ’Ό AC-4 (9) HUMAN REVIEWS
πŸ’Ό AC-4 (10) ENABLE _ DISABLE SECURITY POLICY FILTERS
πŸ’Ό AC-4 (11) CONFIGURATION OF SECURITY POLICY FILTERS
πŸ’Ό AC-4 (12) DATA TYPE IDENTIFIERS
πŸ’Ό AC-4 (13) DECOMPOSITION INTO POLICY-RELEVANT SUBCOMPONENTS
πŸ’Ό AC-4 (14) SECURITY POLICY FILTER CONSTRAINTS
πŸ’Ό AC-4 (15) DETECTION OF UNSANCTIONED INFORMATION
πŸ’Ό AC-4 (16) INFORMATION TRANSFERS ON INTERCONNECTED SYSTEMS
πŸ’Ό AC-4 (17) DOMAIN AUTHENTICATION
πŸ’Ό AC-4 (18) SECURITY ATTRIBUTE BINDING
πŸ’Ό AC-4 (19) VALIDATION OF METADATA
πŸ’Ό AC-4 (20) APPROVED SOLUTIONS
πŸ’Ό AC-4 (21) PHYSICAL _ LOGICAL SEPARATION OF INFORMATION FLOWS
πŸ’Ό AC-4 (22) ACCESS ONLY