id: "AC-04(14)" title: "Security or Privacy Policy Filter Constraints" family: "AC" family_name: "Access Control" sort_id: "ac-04.14" priority: "P1" implementation_level: "system" parent: "AC-04" enhancement: True
Statement
When transferring information between different security domains, implement {{ insert: param, ac-4.14_prm_1 }} requiring fully enumerated formats that restrict data structure and content.
Guidance
Data structure and content restrictions reduce the range of potential malicious or unsanctioned content in cross-domain transactions. Security or privacy policy filters that restrict data structures include restricting file sizes and field lengths. Data content policy filters include encoding formats for character sets, restricting character data fields to only contain alpha-numeric characters, prohibiting special characters, and validating schema structures.
Assessment Objective: when transferring information between different security domains, implemented {{ insert: param, ac-04.14_odp.01 }} require fully enumerated formats that restrict data structure and content;
Assessment Objective: when transferring information between different security domains, implemented {{ insert: param, ac-04.14_odp.02 }} require fully enumerated formats that restrict data structure and content.
Access control policy
information flow control policies
procedures addressing information flow enforcement
system design documentation
system configuration settings and associated documentation
list of security and privacy policy filters
list of data structure policy filters
list of data content policy filters
system audit records
system security plan
privacy plan
other relevant documents or records
System/network administrators
organizational personnel with information security and privacy responsibilities
system developers
Mechanisms implementing information flow enforcement policy
security and privacy policy filters