id: "AC-04(28)" title: "Linear Filter Pipelines" family: "AC" family_name: "Access Control" sort_id: "ac-04.28" priority: "P1" implementation_level: "system" parent: "AC-04" enhancement: True
Statement
When transferring information between different security domains, implement a linear content filter pipeline that is enforced with discretionary and mandatory access controls.
Guidance
Content filtering is the process of inspecting information as it traverses a cross-domain solution and determines if the information meets a predefined policy. The use of linear content filter pipelines ensures that filter processes are non-bypassable and always invoked. In general, the use of parallel filtering architectures for content filtering of a single data type introduces bypass and non-invocation issues.
Assessment Objective
when transferring information between security domains, a linear content filter pipeline is implemented that is enforced with discretionary and mandatory access controls.
Information flow enforcement policy
procedures addressing information flow enforcement
system design documentation
system configuration settings and associated documentation
system audit records
system security plan
other relevant documents or records
Organizational personnel with information flow enforcement responsibilities
system/network administrators
organizational personnel with information security responsibilities
Mechanisms implementing information flow enforcement functions
mechanisms implementing linear content filters