Under active development Content is continuously updated and improved

AC-16(3)Security Attributes

Technical

>Control Description

SECURITY ATTRIBUTES | MAINTENANCE OF ATTRIBUTE ASSOCIATIONS BY INFORMATION SYSTEM The information system maintains the association and integrity of organization-defined security attributes to organization-defined subjects and objects.

>Supplemental Guidance

Maintaining the association and integrity of security attributes to subjects and objects with sufficient assurance helps to ensure that the attribute associations can be used as the basis of automated policy actions. Automated policy actions include, for example, access control decisions or information flow control decisions.

>Tailoring Guidance

This security control/enhancement specifies a very specialized and/or advanced capability that is not required for all systems. Consequently, inclusion in a departmental profile is made on a case by case basis. However, if you are using security labels for access control then the security labels should be cryptographically bound to the data.

Ask AI

Configure your API key to use AI features.