id: "SC-16" title: "Transmission of Security and Privacy Attributes" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-16" priority: "P1" implementation_level: "system" enhancements: - sc-16.1 - sc-16.2 - sc-16.3
Statement
Associate {{ insert: param, sc-16_prm_1 }} with information exchanged between systems and between system components.
Guidance
Security and privacy attributes can be explicitly or implicitly associated with the information contained in organizational systems or system components. Attributes are abstractions that represent the basic properties or characteristics of an entity with respect to protecting information or the management of personally identifiable information. Attributes are typically associated with internal data structures, including records, buffers, and files within the system. Security and privacy attributes are used to implement access control and information flow control policies; reflect special dissemination, management, or distribution instructions, including permitted uses of personally identifiable information; or support other aspects of the information security and privacy policies. Privacy attributes may be used independently or in conjunction with security attributes.
Assessment Objective: {{ insert: param, sc-16_odp.01 }} are associated with information exchanged between systems;
Assessment Objective: {{ insert: param, sc-16_odp.01 }} are associated with information exchanged between system components;
Assessment Objective: {{ insert: param, sc-16_odp.02 }} are associated with information exchanged between systems;
Assessment Objective: {{ insert: param, sc-16_odp.02 }} are associated with information exchanged between system components.
System and communications protection policy
procedures addressing the transmission of security and privacy attributes
access control policy and procedures
information flow control policy
system design documentation
system configuration settings and associated documentation
system audit records
system security plan
privacy plan
other relevant documents or records
System/network administrators
organizational personnel with information security and privacy responsibilities
Mechanisms supporting and/or implementing the transmission of security and privacy attributes between systems