id: "AC-04(28)" title: "Linear Filter Pipelines" family: "AC" family_name: "Access Control" sort_id: "ac-04.28" priority: "P1" implementation_level: "system" parent: "AC-04" enhancement: True


Statement

When transferring information between different security domains, implement a linear content filter pipeline that is enforced with discretionary and mandatory access controls.

Guidance

Content filtering is the process of inspecting information as it traverses a cross-domain solution and determines if the information meets a predefined policy. The use of linear content filter pipelines ensures that filter processes are non-bypassable and always invoked. In general, the use of parallel filtering architectures for content filtering of a single data type introduces bypass and non-invocation issues.

Assessment Objective

when transferring information between security domains, a linear content filter pipeline is implemented that is enforced with discretionary and mandatory access controls.

Information flow enforcement policy

procedures addressing information flow enforcement

system design documentation

system configuration settings and associated documentation

system audit records

system security plan

other relevant documents or records

Organizational personnel with information flow enforcement responsibilities

system/network administrators

organizational personnel with information security responsibilities

Mechanisms implementing information flow enforcement functions

mechanisms implementing linear content filters