id: "AC-04(19)" title: "Validation of Metadata" family: "AC" family_name: "Access Control" sort_id: "ac-04.19" priority: "P1" implementation_level: "system" parent: "AC-04" enhancement: True
Statement
When transferring information between different security domains, implement {{ insert: param, ac-4.19_prm_1 }} on metadata.
Guidance
All information (including metadata and the data to which the metadata applies) is subject to filtering and inspection. Some organizations distinguish between metadata and data payloads (i.e., only the data to which the metadata is bound). Other organizations do not make such distinctions and consider metadata and the data to which the metadata applies to be part of the payload.
Assessment Objective: when transferring information between different security domains, {{ insert: param, ac-04.19_odp.01 }} are implemented on metadata;
Assessment Objective: when transferring information between different security domains, {{ insert: param, ac-04.19_odp.02 }} are implemented on metadata.
Information flow enforcement policy
information flow control policies
procedures addressing information flow enforcement
system design documentation
system configuration settings and associated documentation
list of security policy filtering criteria applied to metadata and data payloads
system audit records
system security plan
privacy plan
other relevant documents or records
Organizational personnel with information flow enforcement responsibilities
system/network administrators
organizational personnel with information security responsibilities
organizational personnel with privacy responsibilities
system developers
Mechanisms implementing information flow enforcement functions
security and policy filters