id: "AC-04(22)" title: "Access Only" family: "AC" family_name: "Access Control" sort_id: "ac-04.22" priority: "P1" implementation_level: "system" parent: "AC-04" enhancement: True
Statement
Provide access from a single device to computing platforms, applications, or data residing in multiple different security domains, while preventing information flow between the different security domains.
Guidance
The system provides a capability for users to access each connected security domain without providing any mechanisms to allow users to transfer data or information between the different security domains. An example of an access-only solution is a terminal that provides a user access to information with different security classifications while assuredly keeping the information separate.
Assessment Objective
access is provided from a single device to computing platforms, applications, or data that reside in multiple different security domains while preventing information flow between the different security domains.
Information flow enforcement policy
procedures addressing information flow enforcement
system design documentation
system configuration settings and associated documentation
system audit records
system security plan
other relevant documents or records
Organizational personnel with information flow enforcement responsibilities
system/network administrators
organizational personnel with information security responsibilities
Mechanisms implementing information flow enforcement functions