id: "AC-04(24)" title: "Internal Normalized Format" family: "AC" family_name: "Access Control" sort_id: "ac-04.24" priority: "P1" implementation_level: "system" parent: "AC-04" enhancement: True
Statement
When transferring information between different security domains, parse incoming data into an internal normalized format and regenerate the data to be consistent with its intended specification.
Guidance
Converting data into normalized forms is one of most of effective mechanisms to stop malicious attacks and large classes of data exfiltration.
Assessment Objective: when transferring information between different security domains, incoming data is parsed into an internal, normalized format;
Assessment Objective: when transferring information between different security domains, the data is regenerated to be consistent with its intended specification.
Information flow enforcement policy
procedures addressing information flow enforcement
system design documentation
system configuration settings and associated documentation
system audit records
system security plan
other relevant documents or records
Organizational personnel with information flow enforcement responsibilities
system/network administrators
organizational personnel with information security responsibilities
Mechanisms implementing information flow enforcement functions