id: "AC-04(21)" title: "Physical or Logical Separation of Information Flows" family: "AC" family_name: "Access Control" sort_id: "ac-04.21" priority: "P1" implementation_level: "system" parent: "AC-04" enhancement: True


Statement

Separate information flows logically or physically using {{ insert: param, ac-4.21_prm_1 }} to accomplish {{ insert: param, ac-04.21_odp.03 }}.

Guidance

Enforcing the separation of information flows associated with defined types of data can enhance protection by ensuring that information is not commingled while in transit and by enabling flow control by transmission paths that are not otherwise achievable. Types of separable information include inbound and outbound communications traffic, service requests and responses, and information of differing security impact or classification levels.

Assessment Objective: information flows are separated logically using {{ insert: param, ac-04.21_odp.01 }} to accomplish {{ insert: param, ac-04.21_odp.03 }};

Assessment Objective: information flows are separated physically using {{ insert: param, ac-04.21_odp.02 }} to accomplish {{ insert: param, ac-04.21_odp.03 }}.

Information flow enforcement policy

information flow control policies

procedures addressing information flow enforcement

system design documentation

system configuration settings and associated documentation

list of required separation of information flows by information types

list of mechanisms and/or techniques used to logically or physically separate information flows

system audit records

system security plan

other relevant documents or records

Organizational personnel with information flow enforcement responsibilities

system/network administrators

organizational personnel with information security responsibilities

system developers

Mechanisms implementing information flow enforcement functions