← Controls / AC

AC-04 Information Flow Enforcement

Access Control

Moderate High

Description

Enforce approved authorizations for controlling the flow of information within the system and between connected systems based on [Assignment: organization-defined information flow control policies].

Supplemental Guidance

Information flow control regulates where information can travel within a system and between systems (in contrast to who is allowed to access the information) and without regard to subsequent accesses to that information. Flow control restrictions include blocking external traffic that claims to be from within the organization, keeping export-controlled information from being transmitted in the clear to the Internet, restricting web requests that are not from the internal web proxy server, and limiting information transfers between organizations based on data structures and content. Transferring information between organizations may require an agreement specifying how the information flow is enforced (see CA-03). Transferring information between systems in different security or privacy domains with different security or privacy policies introduces the risk that such transfers violate one or more domain security or privacy policies. In such situations, information owners/stewards provide guidance at designated policy enforcement points between connected systems. Organizations consider mandating specific architectural solutions to enforce specific security and privacy policies. Enforcement includes prohibiting information transfers between connected systems (i.e., allowing access only), verifying write permissions before accepting information from another security or privacy domain or connected system, employing hardware mechanisms to enforce one-way information flows, and implementing trustworthy regrading mechanisms to reassign security or privacy attributes and labels. Organizations commonly employ information flow control policies and enforcement mechanisms to control the flow of information between designated sources and destinations within systems and between connected systems. Flow control is based on the characteristics of the information and/or the information path. Enforcement occurs, for example, in boundary protection devices that employ rule sets or establish configuration settings that restrict system services, provide a packet-filtering capability based on header information, or provide a message-filtering capability based on message content. Organizations also consider the trustworthiness of filtering and/or inspection mechanisms (i.e., hardware, firmware, and software components) that are critical to information flow enforcement. Control enhancements 3 through 32 primarily address cross-domain solution needs that focus on more advanced filtering techniques, in-depth analysis, and stronger flow enforcement mechanisms implemented in cross-domain products, such as high-assurance guards. Such capabilities are generally not available in commercial off-the-shelf products. Information flow enforcement also applies to control plane traffic (e.g., routing and DNS).

Enhancements (30)

What NIST adds to this control. Select one to read its statement.

AC-04(01) Object Security and Privacy Attributes

Use [Assignment: organization-defined security and privacy attributes] associated with [Assignment: organization-defined information, source, and destination objects] to enforce [Assignment: organization-defined information flow control policies] as a basis for flow control decisions.

AC-04(02) Processing Domains

Use protected processing domains to enforce [Assignment: organization-defined information flow control policies] as a basis for flow control decisions.

AC-04(03) Dynamic Information Flow Control

Enforce [Assignment: organization-defined information flow control policies].

AC-04(04) Flow Control of Encrypted Information High

Prevent encrypted information from bypassing [Assignment: organization-defined information flow control mechanisms] by [Selection (one or more): decrypting the information; blocking the flow of the encrypted information; terminating communications sessions attempting to pass encrypted information; [Assignment: organization-defined procedure or method]].

AC-04(05) Embedded Data Types

Enforce [Assignment: organization-defined limitations] on embedding data types within other data types.

AC-04(06) Metadata

Enforce information flow control based on [Assignment: organization-defined metadata].

AC-04(07) One-way Flow Mechanisms

Enforce one-way information flows through hardware-based flow control mechanisms.

AC-04(08) Security and Privacy Policy Filters

a. Enforce information flow control using [Assignment: organization-defined security or privacy policy filters] as a basis for flow control decisions for [Assignment: organization-defined information flows]; and b. [Selection (one or more): Block; Strip; Modify; Quarantine] data after a filter processing failure in accordance with [Assignment: organization-defined security or privacy policy].

AC-04(09) Human Reviews

Enforce the use of human reviews for [Assignment: organization-defined information flows] under the following conditions: [Assignment: organization-defined conditions].

AC-04(10) Enable and Disable Security or Privacy Policy Filters

Provide the capability for privileged administrators to enable and disable [Assignment: organization-defined security or privacy policy filters] under the following conditions: [Assignment: organization-defined conditions].

AC-04(11) Configuration of Security or Privacy Policy Filters

Provide the capability for privileged administrators to configure [Assignment: organization-defined security or privacy policy filters] to support different security or privacy policies.

AC-04(12) Data Type Identifiers

When transferring information between different security domains, use [Assignment: organization-defined data type identifiers] to validate data essential for information flow decisions.

AC-04(13) Decomposition into Policy-relevant Subcomponents

When transferring information between different security domains, decompose information into [Assignment: organization-defined policy-relevant subcomponents] for submission to policy enforcement mechanisms.

AC-04(14) Security or Privacy Policy Filter Constraints

When transferring information between different security domains, implement [Assignment: organization-defined security or privacy policy filters] requiring fully enumerated formats that restrict data structure and content.

AC-04(15) Detection of Unsanctioned Information

When transferring information between different security domains, examine the information for the presence of [Assignment: organization-defined unsanctioned information] and prohibit the transfer of such information in accordance with the [Assignment: organization-defined security or privacy policy].

AC-04(17) Domain Authentication

Uniquely identify and authenticate source and destination points by [Selection (one or more): organization; system; application; service; individual] for information transfer.

AC-04(19) Validation of Metadata

When transferring information between different security domains, implement [Assignment: organization-defined security or privacy policy filters] on metadata.

AC-04(20) Approved Solutions

Employ [Assignment: organization-defined solutions in approved configurations] to control the flow of [Assignment: organization-defined information] across security domains.

AC-04(21) Physical or Logical Separation of Information Flows

Separate information flows logically or physically using [Assignment: organization-defined mechanisms and/or techniques] to accomplish [Assignment: organization-defined required separations by types of information].

AC-04(22) Access Only

Provide access from a single device to computing platforms, applications, or data residing in multiple different security domains, while preventing information flow between the different security domains.

AC-04(23) Modify Non-releasable Information

When transferring information between different security domains, modify non-releasable information by implementing [Assignment: organization-defined modification action].

AC-04(24) Internal Normalized Format

When transferring information between different security domains, parse incoming data into an internal normalized format and regenerate the data to be consistent with its intended specification.

AC-04(25) Data Sanitization

When transferring information between different security domains, sanitize data to minimize [Selection (one or more): delivery of malicious content, command and control of malicious code, malicious code augmentation, and steganography encoded data; spillage of sensitive information] in accordance with [Assignment: organization-defined policy].

AC-04(26) Audit Filtering Actions

When transferring information between different security domains, record and audit content filtering actions and results for the information being filtered.

AC-04(27) Redundant/Independent Filtering Mechanisms

When transferring information between different security domains, implement content filtering solutions that provide redundant and independent filtering mechanisms for each data type.

AC-04(28) Linear Filter Pipelines

When transferring information between different security domains, implement a linear content filter pipeline that is enforced with discretionary and mandatory access controls.

AC-04(29) Filter Orchestration Engines

When transferring information between different security domains, employ content filter orchestration engines to ensure that: a. Content filtering mechanisms successfully complete execution without errors; and b. Content filtering actions occur in the correct order and comply with [Assignment: organization-defined policy].

AC-04(30) Filter Mechanisms Using Multiple Processes

When transferring information between different security domains, implement content filtering mechanisms using multiple processes.

AC-04(31) Failed Content Transfer Prevention

When transferring information between different security domains, prevent the transfer of failed content to the receiving domain.

AC-04(32) Process Requirements for Information Transfer

When transferring information between different security domains, the process that transfers information between filter pipelines: a. Does not filter message content; b. Validates filtering metadata; c. Ensures the content associated with the filtering metadata has successfully completed filtering; and d. Transfers the content to the destination filter pipeline.

Withdrawn by NIST:

  • AC-04(16) Information Transfers on Interconnected Systems, now in AC-04
  • AC-04(18) Security Attribute Binding, now in AC-16

MITRE ATT&CK Techniques (158)

ATT&CK v16.1

Techniques mitigated by this control, mapped via CTID.

Reconnaissance 5 Initial Access 9 Execution 10 Persistence 20 Privilege Escalation 15 Defense Evasion 24 Credential Access 17 Discovery 4 Lateral Movement 10 Collection 18 Command & Control 37 Exfiltration 14 Impact 11
Show all 158 techniques grouped by tactic

Defense Evasion

Command & Control

Compliance Mappings

ISO 27001:2022

A.5.14A.8.3A.8.12A.8.20A.8.22A.8.23

ISO 27002:2022

5.148.38.128.208.23

COBIT 2019

APO14DSS05DSS06

CIS Controls v8

CIS 3CIS 3.8CIS 3.12CIS 3.13CIS 9.3CIS 12CIS 13.4CIS 13.10

NIST CSF 2.0

DE.CM-09ID.AM-03PR.DS-10PR.IR-01

SOC 2 TSC

CC6.1CC6.1-POF6CC6.6CC6.6-POF1

PCI DSS v4.0.1

1.21.3

CSA CCM v4

DSP-05DSP-10IVS-03IVS-06UEM-11

CSA AICM v1

AIS-08DSP-05DSP-10DSP-22I&S-03I&S-06UEM-11

FINOS CCC

CCC-C05CCC-C09

ISO 42001:2023

A.9.4

IEC 62443

3-3 SR 2.13-3 SR 5.1

NIS2 Directive

Art. 21(2)(i)

PRA Operational Resilience

SS2/21-11.1

MAS TRM

9

BSI IT-Grundschutz

NET.1.1ORP.4

ANSSI

Hygiene.23Hygiene.27SecNumCloud.14.1

FINMA Circular 2023/1

IV.B.d(59)IV.C(62)IV.C(63)

OSFI B-13

B-13.3.2

EU GDPR

Art.5(1)(f)Art.32(1)(a)Art.44Art.46(1)

EU DORA

Art.9(4)(a)

BIO2

5.148.38.128.208.23

RBI CSF

Annex1.4Annex1.15ITGRCA.19

FISC Security Guidelines

FISC.T2FISC.T3FISC.T5FISC.T8FISC.T13

LGPD + BCB 4893

BCB.Art.3BCB.Art.13BCB.Art.14BCB.OpenFinanceBCB.PIXLGPD.Art.23-26LGPD.Art.33-36LGPD.Art.46

HKMA TM-E-1

TME1.10.1TME1.10.3

MLPS 2.0

8.1.2.18.1.3.28.28.5

DNB Good Practice

DNB.12.3DNB.18.4DNB.18.5

EU CRA

CRA.I.2j

SWIFT CSCF

SWIFT.1.1SWIFT.1.3SWIFT.1.4SWIFT.1.5SWIFT.2.4A

SAMA CSF

3.13.3

NCA ECC

2-52-72-14

UAE IA

T8T9

CBB TM

TM-6TM-8

Qatar NIA

ACCS

CBUAE

CR-4CR-5

CBE CSF

CTO-1CTO-2CTO-5CTO-6CTO-8

SA JS2

JS2-7.1JS2-8.2

CBN CSF

Part3.2Part3.4Part5.2

BoG CISD

CISD-VIIICISD-XICISD-XIII

POPIA

s19s72

BoM CTRM

3.23.10

IOSCO Cyber Resilience

PFMI-20PROT-2

BCBS 239

Principle 11

CPMI-IOSCO PFMI

CG.PRPFMI.P17PFMI.P22

FFIEC IS

II.C.6II.C.9II.C.13II.C.13(b)

NYDFS 500

500.18

HIPAA Security Rule

§164.308(a)(4)(i)§164.308(a)(4)(ii)(A)§164.314(b)(1)§164.314(b)(2)

ECB CROE

CROE.2.3.5

EBA ICT Guidelines

3.4.2

SEBI CSCRF

DATALOCEMAIL-SECPR.AAPR.DSPR.NS

BOT Cyber Resilience

Ch2.2Ch2.4

CMMC 2.0

AC

NERC CIP

CIP-005-7

10 CFR 73.54

73.54(c)(1)73.54(c)(2)

TSA Pipeline SD

SD-2 Sec A

IEEE 1686-2022

5.6

FERC CIP Orders

Order 887Order 2222

DOE C2M2 v2.1

ARCHITECTURE

API 1164

Sec 5Sec 8

AWIA

AWWA Sec 4

IAEA NSS 17-T

Sec 5.1Sec 5.6

PCI PTS v6

EJ

FIPS 140-3

FIPS 140-3 §7.3

PCI HSM

3

Common Criteria

CC Part 2 — FDP

ISAE 3402

Clause 4

Solvency II

Art.49(3)DR.266-DataSecEIOPA-Cloud-GL9EIOPA-ICT-4.6

Lloyd's Minimum Standards

BP2.2MS6.1MS8.9MS13.2

NAIC Insurance Data Security

4B8

HITRUST CSF v11

01.b09.e

FDA Cybersecurity Guidance

SA-4TM-2

ISO 27799

9.513.113.2H.2H.4

NHS DSPT

NDG-9.2NDG-9.5

OWASP MASVS v2.1

MASVS-PLATFORM-1MASVS-PLATFORM-2MASVS-PLATFORM-3MASVS-STORAGE-2

CCSS v9.0

1.05.4

MiCA

Art.63(1)Art.68(1)Art.76(1)

Basel SCO60

SCO60.64

BSSC Standards

NOS-04TIS-04

SEC Custody (Digital Assets)

SEC-CD-04

India DPDPA

Act.16Rules.13(4)Rules.15

ISO 17799 (legacy)

10.6.211.4.511.4.611.4.7

COBIT 4.1 (legacy)

DS5.10