id: "AC-04(19)" title: "Validation of Metadata" family: "AC" family_name: "Access Control" sort_id: "ac-04.19" priority: "P1" implementation_level: "system" parent: "AC-04" enhancement: True


Statement

When transferring information between different security domains, implement {{ insert: param, ac-4.19_prm_1 }} on metadata.

Guidance

All information (including metadata and the data to which the metadata applies) is subject to filtering and inspection. Some organizations distinguish between metadata and data payloads (i.e., only the data to which the metadata is bound). Other organizations do not make such distinctions and consider metadata and the data to which the metadata applies to be part of the payload.

Assessment Objective: when transferring information between different security domains, {{ insert: param, ac-04.19_odp.01 }} are implemented on metadata;

Assessment Objective: when transferring information between different security domains, {{ insert: param, ac-04.19_odp.02 }} are implemented on metadata.

Information flow enforcement policy

information flow control policies

procedures addressing information flow enforcement

system design documentation

system configuration settings and associated documentation

list of security policy filtering criteria applied to metadata and data payloads

system audit records

system security plan

privacy plan

other relevant documents or records

Organizational personnel with information flow enforcement responsibilities

system/network administrators

organizational personnel with information security responsibilities

organizational personnel with privacy responsibilities

system developers

Mechanisms implementing information flow enforcement functions

security and policy filters