id: "AC-16(01)" title: "Dynamic Attribute Association" family: "AC" family_name: "Access Control" sort_id: "ac-16.01" priority: "P1" implementation_level: "system" parent: "AC-16" enhancement: True
Statement
Dynamically associate security and privacy attributes with {{ insert: param, ac-16.1_prm_1 }} in accordance with the following security and privacy policies as information is created and combined: {{ insert: param, ac-16.1_prm_2 }}.
Guidance
Dynamic association of attributes is appropriate whenever the security or privacy characteristics of information change over time. Attributes may change due to information aggregation issues (i.e., characteristics of individual data elements are different from the combined elements), changes in individual access authorizations (i.e., privileges), changes in the security category of information, or changes in security or privacy policies. Attributes may also change situationally.
Assessment Objective: security attributes are dynamically associated with {{ insert: param, ac-16.01_odp.01 }} in accordance with the following security policies as information is created and combined: {{ insert: param, ac-16.01_odp.05 }};
Assessment Objective: security attributes are dynamically associated with {{ insert: param, ac-16.01_odp.02 }} in accordance with the following security policies as information is created and combined: {{ insert: param, ac-16.01_odp.05 }};
Assessment Objective: privacy attributes are dynamically associated with {{ insert: param, ac-16.01_odp.03 }} in accordance with the following privacy policies as information is created and combined: {{ insert: param, ac-16.01_odp.06 }};
Assessment Objective: privacy attributes are dynamically associated with {{ insert: param, ac-16.01_odp.04 }} in accordance with the following privacy policies as information is created and combined: {{ insert: param, ac-16.01_odp.06 }}.
Access control policy
procedures addressing dynamic association of security and privacy attributes to information
system design documentation
system configuration settings and associated documentation
system audit records
system security plan
privacy plan
other relevant documents or records
System/network administrators
organizational personnel with information security and privacy responsibilities
system developers
Automated mechanisms implementing dynamic association of security and privacy attributes to information