AC-4(3)—Information Flow Enforcement
Technical
>Control Description
INFORMATION FLOW ENFORCEMENT | DYNAMIC INFORMATION FLOW CONTROL The information system enforces dynamic information flow control based on ⚙organization-defined policies.
>Supplemental Guidance
Organizational policies regarding dynamic information flow control include, for example, allowing or disallowing information flows based on changing conditions or mission/operational considerations. Changing conditions include, for example, changes in organizational risk tolerance due to changes in the immediacy of mission/business needs, changes in the threat environment, and detection of potentially harmful or adverse events. Related control: SI-4.
>Tailoring Guidance
This security control/enhancement specifies a very specialized and/or advanced capability that is not required for all systems. Consequently, inclusion in a departmental profile is made on a case by case basis.
Ask AI
Configure your API key to use AI features.