id: "AC-04(29)" title: "Filter Orchestration Engines" family: "AC" family_name: "Access Control" sort_id: "ac-04.29" priority: "P1" implementation_level: "system" parent: "AC-04" enhancement: True


Statement

When transferring information between different security domains, employ content filter orchestration engines to ensure that:

Content filtering mechanisms successfully complete execution without errors; and

Content filtering actions occur in the correct order and comply with {{ insert: param, ac-04.29_odp }}.

Guidance

Content filtering is the process of inspecting information as it traverses a cross-domain solution and determines if the information meets a predefined security policy. An orchestration engine coordinates the sequencing of activities (manual and automated) in a content filtering process. Errors are defined as either anomalous actions or unexpected termination of the content filter process. This is not the same as a filter failing content due to non-compliance with policy. Content filter reports are a commonly used mechanism to ensure that expected filtering actions are completed successfully.

Assessment Objective: when transferring information between security domains, content filter orchestration engines are employed to ensure that content-filtering mechanisms successfully complete execution without errors;

Assessment Objective: when transferring information between security domains, content filter orchestration engines are employed to ensure that content-filtering actions occur in the correct order;

Assessment Objective: when transferring information between security domains, content filter orchestration engines are employed to ensure that content-filtering actions comply with {{ insert: param, ac-04.29_odp }}.

Information flow enforcement policy

procedures addressing information flow enforcement

system design documentation

system configuration settings and associated documentation

system audit records

system security plan

other relevant documents or records

Organizational personnel with information flow enforcement responsibilities

system/network administrators

organizational personnel with information security responsibilities

Mechanisms implementing information flow enforcement functions

mechanisms implementing content filter orchestration engines