AC-16(3)—Security Attributes
Technical
>Control Description
SECURITY ATTRIBUTES | MAINTENANCE OF ATTRIBUTE ASSOCIATIONS BY INFORMATION SYSTEM The information system maintains the association and integrity of ⚙organization-defined security attributes to ⚙organization-defined subjects and objects.
>Supplemental Guidance
Maintaining the association and integrity of security attributes to subjects and objects with sufficient assurance helps to ensure that the attribute associations can be used as the basis of automated policy actions. Automated policy actions include, for example, access control decisions or information flow control decisions.
>Tailoring Guidance
This security control/enhancement specifies a very specialized and/or advanced capability that is not required for all systems. Consequently, inclusion in a departmental profile is made on a case by case basis. However, if you are using security labels for access control then the security labels should be cryptographically bound to the data.
Ask AI
Configure your API key to use AI features.