id: "AC-04(03)" title: "Dynamic Information Flow Control" family: "AC" family_name: "Access Control" sort_id: "ac-04.03" priority: "P1" implementation_level: "system" parent: "AC-04" enhancement: True


Statement

Enforce {{ insert: param, ac-04.03_odp }}.

Guidance

Organizational policies regarding dynamic information flow control include allowing or disallowing information flows based on changing conditions or mission or operational considerations. Changing conditions include changes in risk tolerance due to changes in the immediacy of mission or business needs, changes in the threat environment, and detection of potentially harmful or adverse events.

Assessment Objective

{{ insert: param, ac-04.03_odp }} are enforced.

Access control policy

information flow control policies

procedures addressing information flow enforcement

system design documentation

system security architecture and associated documentation

system configuration settings and associated documentation

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

system developers

Mechanisms implementing information flow enforcement policy