id: "AC-04(29)" title: "Filter Orchestration Engines" family: "AC" family_name: "Access Control" sort_id: "ac-04.29" priority: "P1" implementation_level: "system" parent: "AC-04" enhancement: True
Statement
When transferring information between different security domains, employ content filter orchestration engines to ensure that:
Content filtering mechanisms successfully complete execution without errors; and
Content filtering actions occur in the correct order and comply with {{ insert: param, ac-04.29_odp }}.
Guidance
Content filtering is the process of inspecting information as it traverses a cross-domain solution and determines if the information meets a predefined security policy. An orchestration engine coordinates the sequencing of activities (manual and automated) in a content filtering process. Errors are defined as either anomalous actions or unexpected termination of the content filter process. This is not the same as a filter failing content due to non-compliance with policy. Content filter reports are a commonly used mechanism to ensure that expected filtering actions are completed successfully.
Assessment Objective: when transferring information between security domains, content filter orchestration engines are employed to ensure that content-filtering mechanisms successfully complete execution without errors;
Assessment Objective: when transferring information between security domains, content filter orchestration engines are employed to ensure that content-filtering actions occur in the correct order;
Assessment Objective: when transferring information between security domains, content filter orchestration engines are employed to ensure that content-filtering actions comply with {{ insert: param, ac-04.29_odp }}.
Information flow enforcement policy
procedures addressing information flow enforcement
system design documentation
system configuration settings and associated documentation
system audit records
system security plan
other relevant documents or records
Organizational personnel with information flow enforcement responsibilities
system/network administrators
organizational personnel with information security responsibilities
Mechanisms implementing information flow enforcement functions
mechanisms implementing content filter orchestration engines