id: "AC-04(14)" title: "Security or Privacy Policy Filter Constraints" family: "AC" family_name: "Access Control" sort_id: "ac-04.14" priority: "P1" implementation_level: "system" parent: "AC-04" enhancement: True


Statement

When transferring information between different security domains, implement {{ insert: param, ac-4.14_prm_1 }} requiring fully enumerated formats that restrict data structure and content.

Guidance

Data structure and content restrictions reduce the range of potential malicious or unsanctioned content in cross-domain transactions. Security or privacy policy filters that restrict data structures include restricting file sizes and field lengths. Data content policy filters include encoding formats for character sets, restricting character data fields to only contain alpha-numeric characters, prohibiting special characters, and validating schema structures.

Assessment Objective: when transferring information between different security domains, implemented {{ insert: param, ac-04.14_odp.01 }} require fully enumerated formats that restrict data structure and content;

Assessment Objective: when transferring information between different security domains, implemented {{ insert: param, ac-04.14_odp.02 }} require fully enumerated formats that restrict data structure and content.

Access control policy

information flow control policies

procedures addressing information flow enforcement

system design documentation

system configuration settings and associated documentation

list of security and privacy policy filters

list of data structure policy filters

list of data content policy filters

system audit records

system security plan

privacy plan

other relevant documents or records

System/network administrators

organizational personnel with information security and privacy responsibilities

system developers

Mechanisms implementing information flow enforcement policy

security and privacy policy filters