id: "AC-04(05)" title: "Embedded Data Types" family: "AC" family_name: "Access Control" sort_id: "ac-04.05" priority: "P1" implementation_level: "system" parent: "AC-04" enhancement: True
Statement
Enforce {{ insert: param, ac-04.05_odp }} on embedding data types within other data types.
Guidance
Embedding data types within other data types may result in reduced flow control effectiveness. Data type embedding includes inserting files as objects within other files and using compressed or archived data types that may include multiple embedded data types. Limitations on data type embedding consider the levels of embedding and prohibit levels of data type embedding that are beyond the capability of the inspection tools.
Assessment Objective
{{ insert: param, ac-04.05_odp }} are enforced on embedding data types within other data types.
Access control policy
procedures addressing information flow enforcement
system design documentation
system configuration settings and associated documentation
list of limitations to be enforced on embedding data types within other data types
system audit records
system security plan
other relevant documents or records
System/network administrators
organizational personnel with information security responsibilities
system developers
Mechanisms implementing information flow enforcement policy