NIST 800-53 Rev 5

424 controls available

AC-4moderatehigh

Information Flow Enforcement

Access Control

Control Statement

Enforce approved authorizations for controlling the flow of information within the system and between connected systems based on {{ insert: param, ac-04_odp }}.

Discussion

Information flow control regulates where information can travel within a system and between systems (in contrast to who is allowed to access the information) and without regard to subsequent accesses to that information. Flow control restrictions include blocking external traffic that claims to be from within the organization, keeping export-controlled information from being transmitted in the clear to the Internet, restricting web requests that are not from the internal web proxy server, and limiting information transfers between organizations based on data structures and content. Transferring information between organizations may require an agreement specifying how the information flow is enforced (see [CA-3](#ca-3) ). Transferring information between systems in different security or privacy domains with different security or privacy policies introduces the risk that such transfers violate one or more domain security or privacy policies. In such situations, information owners/stewards provide guidance at designated policy enforcement points between connected systems. Organizations consider mandating specific architectural solutions to enforce specific security and privacy policies. Enforcement includes prohibiting information transfers between connected systems (i.e., allowing access only), verifying write permissions before accepting information from another security or privacy domain or connected system, employing hardware mechanisms to enforce one-way information flows, and implementing trustworthy regrading mechanisms to reassign security or privacy attributes and labels. Organizations commonly employ information flow control policies and enforcement mechanisms to control the flow of information between designated sources and destinations within systems and between connected systems. Flow control is based on the characteristics of the information and/or the information path. Enforcement occurs, for example, in boundary protection devices that employ rule sets or establish configuration settings that restrict system services, provide a packet-filtering capability based on header information, or provide a message-filtering capability based on message content. Organizations also consider the trustworthiness of filtering and/or inspection mechanisms (i.e., hardware, firmware, and software components) that are critical to information flow enforcement. Control enhancements 3 through 32 primarily address cross-domain solution needs that focus on more advanced filtering techniques, in-depth analysis, and stronger flow enforcement mechanisms implemented in cross-domain products, such as high-assurance guards. Such capabilities are generally not available in commercial off-the-shelf products. Information flow enforcement also applies to control plane traffic (e.g., routing and DNS).

Framework
NIST SP 800-53 Rev 5
Family
Access Control
Baselines
moderate, high

Related Frameworks

7 paths across 2 frameworks
NIST 800-1711 mapping
3.1.3
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI6 mappings
CCI-001368
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001414
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001548
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001549
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001550
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001551
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

127 STIGs reach this control through 80 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Operating System — Server

2 STIGs

Operating System — Mainframe

3 STIGs
Mainframe Product Security Requirements Guide
V3R42025-09-101 of 194 findings match
Mainframe Product Security Requirements Guide
32024-12-051 of 193 findings match

Network Device

86 STIGs
Router Security Requirements Guide
V5R22025-09-1029 of 123 findings match
Show 78 more STIGs in this category →
Router Security Requirements Guide
52024-05-2823 of 108 findings match
Application Layer Gateway Security Requirements Guide
V2R32025-09-1512 of 160 findings match
Layer 2 Switch Security Requirements Guide
V3R42026-02-124 of 36 findings match
Firewall Security Requirements Guide
V3R32025-09-223 of 35 findings match
Firewall Security Requirements Guide
32024-12-042 of 34 findings match
Cisco ASA NDM Security Technical Implementation Guide
V2R42025-12-081 of 47 findings match
Cisco ASA VPN Security Technical Implementation Guide
V2R22024-08-221 of 41 findings match
F5 NGINX Security Technical Implementation Guide
V1R12026-01-071 of 32 findings match
Network Device Management Security Requirements Guide
V5R32025-02-111 of 104 findings match
Network Device Management Security Requirements Guide
V5R42025-09-101 of 105 findings match
RUCKUS ICX NDM Security Technical Implementation Guide
V1R12025-05-281 of 25 findings match
SDN Controller Security Requirements Guide
22024-05-281 of 34 findings match

Web / Application Server

8 STIGs

Virtualization / Container

12 STIGs

Cloud / Identity Service

1 STIG

Endpoint Security Management

9 STIGs
Tanium 7.x Security Technical Implementation Guide
V2R32025-05-148 of 98 findings match
HYCU Protege Security Technical Implementation Guide
V1R22026-03-041 of 55 findings match
Show 1 more STIG in this category →

Productivity Application

4 STIGs

Uncategorized

2 STIGs