id: "AC-04(23)" title: "Modify Non-releasable Information" family: "AC" family_name: "Access Control" sort_id: "ac-04.23" priority: "P1" implementation_level: "system" parent: "AC-04" enhancement: True


Statement

When transferring information between different security domains, modify non-releasable information by implementing {{ insert: param, ac-04.23_odp }}.

Guidance

Modifying non-releasable information can help prevent a data spill or attack when information is transferred across security domains. Modification actions include masking, permutation, alteration, removal, or redaction.

Assessment Objective

when transferring information between security domains, non-releasable information is modified by implementing {{ insert: param, ac-04.23_odp }}.

Information flow enforcement policy

procedures addressing information flow enforcement

system design documentation

system configuration settings and associated documentation

system audit records

system security plan

other relevant documents or records

Organizational personnel with information flow enforcement responsibilities

system/network administrators

organizational personnel with information security responsibilities

Mechanisms implementing information flow enforcement functions