id: "AC-04(26)" title: "Audit Filtering Actions" family: "AC" family_name: "Access Control" sort_id: "ac-04.26" priority: "P1" implementation_level: "system" parent: "AC-04" enhancement: True


Statement

When transferring information between different security domains, record and audit content filtering actions and results for the information being filtered.

Guidance

Content filtering is the process of inspecting information as it traverses a cross-domain solution and determines if the information meets a predefined policy. Content filtering actions and the results of filtering actions are recorded for individual messages to ensure that the correct filter actions were applied. Content filter reports are used to assist in troubleshooting actions by, for example, determining why message content was modified and/or why it failed the filtering process. Audit events are defined in AU-2 . Audit records are generated in AU-12.

Assessment Objective: when transferring information between different security domains, content-filtering actions are recorded and audited;

Assessment Objective: when transferring information between different security domains, results for the information being filtered are recorded and audited.

Information flow enforcement policy

procedures addressing information flow enforcement

system design documentation

system configuration settings and associated documentation

system audit records

system security plan

other relevant documents or records

Organizational personnel with information flow enforcement responsibilities

system/network administrators

organizational personnel with information security responsibilities

Mechanisms implementing information flow enforcement functions

mechanisms implementing content filtering

mechanisms recording and auditing content filtering