# AC-04 Information Flow Enforcement

NIST SP 800-53 control. Family: AC Access Control. Function: preventative. Baselines: moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: Enforce approved authorizations for controlling the flow of information within the system and between connected systems based on [Assignment: organization-defined information flow control policies].
Guidance: Information flow control regulates where information can travel within a system and between systems (in contrast to who is allowed to access the information) and without regard to subsequent accesses to that information. Flow control restrictions include blocking external traffic that claims to be from within the organization, keeping export-controlled information from being transmitted in the clear to the Internet, restricting web requests that are not from the internal web proxy server, and limiting information transfers between organizations based on data structures and content. Transferring information between organizations may require an agreement specifying how the information flow is enforced (see CA-03). Transferring information between systems in different security or privacy domains with different security or privacy policies introduces the risk that such transfers violate one or more domain security or privacy policies. In such situations, information owners/stewards provide guidance at designated policy enforcement points between connected systems. Organizations consider mandating specific architectural solutions to enforce specific security and privacy policies. Enforcement includes prohibiting information transfers between connected systems (i.e., allowing access only), verifying write permissions before accepting information from another security or privacy domain or connected system, employing hardware mechanisms to enforce one-way information flows, and implementing trustworthy regrading mechanisms to reassign security or privacy attributes and labels. Organizations commonly employ information flow control policies and enforcement mechanisms to control the flow of information between designated sources and destinations within systems and between connected systems. Flow control is based on the characteristics of the information and/or the information path. Enforcement occurs, for example, in boundary protection devices that employ rule sets or establish configuration settings that restrict system services, provide a packet-filtering capability based on header information, or provide a message-filtering capability based on message content. Organizations also consider the trustworthiness of filtering and/or inspection mechanisms (i.e., hardware, firmware, and software components) that are critical to information flow enforcement. Control enhancements 3 through 32 primarily address cross-domain solution needs that focus on more advanced filtering techniques, in-depth analysis, and stronger flow enforcement mechanisms implemented in cross-domain products, such as high-assurance guards. Such capabilities are generally not available in commercial off-the-shelf products. Information flow enforcement also applies to control plane traffic (e.g., routing and DNS).

## Enhancements (30)
- AC-04(01) Object Security and Privacy Attributes
- AC-04(02) Processing Domains
- AC-04(03) Dynamic Information Flow Control
- AC-04(04) Flow Control of Encrypted Information. Baselines: high
- AC-04(05) Embedded Data Types
- AC-04(06) Metadata
- AC-04(07) One-way Flow Mechanisms
- AC-04(08) Security and Privacy Policy Filters
- AC-04(09) Human Reviews
- AC-04(10) Enable and Disable Security or Privacy Policy Filters
- AC-04(11) Configuration of Security or Privacy Policy Filters
- AC-04(12) Data Type Identifiers
- AC-04(13) Decomposition into Policy-relevant Subcomponents
- AC-04(14) Security or Privacy Policy Filter Constraints
- AC-04(15) Detection of Unsanctioned Information
- AC-04(17) Domain Authentication
- AC-04(19) Validation of Metadata
- AC-04(20) Approved Solutions
- AC-04(21) Physical or Logical Separation of Information Flows
- AC-04(22) Access Only
- AC-04(23) Modify Non-releasable Information
- AC-04(24) Internal Normalized Format
- AC-04(25) Data Sanitization
- AC-04(26) Audit Filtering Actions
- AC-04(27) Redundant/Independent Filtering Mechanisms
- AC-04(28) Linear Filter Pipelines
- AC-04(29) Filter Orchestration Engines
- AC-04(30) Filter Mechanisms Using Multiple Processes
- AC-04(31) Failed Content Transfer Prevention
- AC-04(32) Process Requirements for Information Transfer
Withdrawn by NIST: AC-04(16) (now in AC-04); AC-04(18) (now in AC-16).
Each enhancement's statement: /api/v1/controls/AC-04?fields=enhancements

## Patterns that use it (21)
- Critical (11): SP-005 SOA Internal Service Usage Pattern; SP-013 Data Security Pattern; SP-015 Secure Remote Working; SP-016 DMZ Module; SP-017 Secure Network Zone Module; SP-027 Secure LLM Usage; SP-029 Zero Trust Architecture; SP-030 API Security; SP-039 Client-Side Encryption and Data Privacy; SP-047 Secure Agentic AI Frameworks; SP-054 CBDC and Digital Currency Infrastructure (draft)
- Important (10): SP-011 Cloud Computing Pattern; SP-020 Email Transport Layer Security (TLS) Pattern; SP-025 Advanced Monitoring and Detection; SP-028 Secure DevOps Pipeline Pattern; SP-031 Security Monitoring and Response; SP-036 Incident Response; SP-050 Mobile Security Architecture (draft); SP-051 Tokenised Asset Security Architecture (draft); SP-052 Decentralised Identity & Verifiable Credentials (draft); SP-053 Zero-Knowledge Proof Architecture (draft)

## Clauses by framework (81 frameworks)
- iso_27001_2022: A.5.14, A.8.3, A.8.12, A.8.20, A.8.22, A.8.23. OSA's own, not in NIST's crosswalk: A.8.3, A.8.12, A.8.20
- iso_27002_2022: 5.14, 8.3, 8.12, 8.20, 8.23
- cobit_2019: APO14, DSS05, DSS06
- pci_dss_v4: 1.2, 1.3
- nist_csf_2: DE.CM-09, ID.AM-03, PR.DS-10, PR.IR-01
- cis_controls_v8: CIS 3, CIS 3.8, CIS 3.12, CIS 3.13, CIS 9.3, CIS 12, CIS 13.4, CIS 13.10
- soc2_tsc: CC6.1, CC6.1-POF6, CC6.6, CC6.6-POF1
- finos_ccc: CCC-C05, CCC-C09
- iso_42001_2023: A.9.4
- iec_62443: 3-3 SR 2.1, 3-3 SR 5.1
- nis2: Art. 21(2)(i)
- mas_trm: 9
- pra_op_resilience: SS2/21-11.1
- bsi_grundschutz: NET.1.1, ORP.4
- anssi: Hygiene.23, Hygiene.27, SecNumCloud.14.1
- osfi_b13: B-13.3.2
- finma_circular: IV.B.d(59), IV.C(62), IV.C(63)
- gdpr: Art.5(1)(f), Art.32(1)(a), Art.44, Art.46(1)
- dora: Art.9(4)(a)
- bio2: 5.14, 8.3, 8.12, 8.20, 8.23
- rbi_csf: Annex1.4, Annex1.15, ITGRCA.19
- fisc: FISC.T2, FISC.T3, FISC.T5, FISC.T8, FISC.T13
- lgpd_bcb: BCB.Art.3, BCB.Art.13, BCB.Art.14, BCB.OpenFinance, BCB.PIX, LGPD.Art.23-26, LGPD.Art.33-36, LGPD.Art.46
- hkma_tme1: TME1.10.1, TME1.10.3
- mlps_2: 8.1.2.1, 8.1.3.2, 8.2, 8.5
- dnb_good_practice: DNB.12.3, DNB.18.4, DNB.18.5
- cra: CRA.I.2j
- swift_cscf: SWIFT.1.1, SWIFT.1.3, SWIFT.1.4, SWIFT.1.5, SWIFT.2.4A
- cbb_tm: TM-6, TM-8
- cbuae: CR-4, CR-5
- nca_ecc: 2-5, 2-7, 2-14
- qatar_nia: AC, CS
- sama_csf: 3.1, 3.3
- uae_ia: T8, T9
- bog_cisd: CISD-VIII, CISD-XI, CISD-XIII
- bom_ctrm: 3.2, 3.10
- cbe_csf: CTO-1, CTO-2, CTO-5, CTO-6, CTO-8
- cbn_csf: Part3.2, Part3.4, Part5.2
- popia: s19, s72
- sa_js2: JS2-7.1, JS2-8.2
- bcbs_239: Principle 11
- bot_cyber: Ch2.2, Ch2.4
- cpmi_pfmi: CG.PR, PFMI.P17, PFMI.P22
- eba_ict: 3.4.2
- ecb_croe: CROE.2.3.5
- ffiec_is: II.C.6, II.C.9, II.C.13, II.C.13(b)
- hipaa_sr: §164.308(a)(4)(i), §164.308(a)(4)(ii)(A), §164.314(b)(1), §164.314(b)(2)
- iosco_cyber: PFMI-20, PROT-2
- nydfs_500: 500.18
- sebi_cscrf: DATALOC, EMAIL-SEC, PR.AA, PR.DS, PR.NS
- cmmc_2: AC
- nerc_cip: CIP-005-7
- nrc_73_54: 73.54(c)(1), 73.54(c)(2)
- tsa_psd: SD-2 Sec A
- ieee_1686: 5.6
- ferc_cip: Order 887, Order 2222
- doe_c2m2: ARCHITECTURE
- api_1164: Sec 5, Sec 8
- awia: AWWA Sec 4
- iaea_nss: Sec 5.1, Sec 5.6
- pci_pts: E, J
- fips_140: FIPS 140-3 §7.3
- pci_hsm: 3
- common_criteria: CC Part 2 — FDP
- isae_3402: Clause 4
- fda_cyber: SA-4, TM-2
- hitrust_csf: 01.b, 09.e
- iso_27799: 9.5, 13.1, 13.2, H.2, H.4
- lloyds_ms: BP2.2, MS6.1, MS8.9, MS13.2
- naic_ds: 4B, 8
- nhs_dspt: NDG-9.2, NDG-9.5
- solvency_ii: Art.49(3), DR.266-DataSec, EIOPA-Cloud-GL9, EIOPA-ICT-4.6
- owasp_masvs_v2: MASVS-PLATFORM-1, MASVS-PLATFORM-2, MASVS-PLATFORM-3, MASVS-STORAGE-2
- csa_ccm_v4: DSP-05, DSP-10, IVS-03, IVS-06, UEM-11
- csa_aicm: AIS-08, DSP-05, DSP-10, DSP-22, I&S-03, I&S-06, UEM-11
- ccss_v9: 1.05.4
- mica: Art.63(1), Art.68(1), Art.76(1)
- basel_sco60: SCO60.64
- bssc: NOS-04, TIS-04
- sec_custody_digital: SEC-CD-04
- dpdpa: Act.16, Rules.13(4), Rules.15
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/AC-04
- Clauses only: /api/v1/controls/AC-04?fields=mappings
- Page for people: /controls/ac-04/
