Under active development Content is continuously updated and improved

AC-4(3)Information Flow Enforcement

Technical

>Control Description

INFORMATION FLOW ENFORCEMENT | DYNAMIC INFORMATION FLOW CONTROL The information system enforces dynamic information flow control based on organization-defined policies.

>Supplemental Guidance

Organizational policies regarding dynamic information flow control include, for example, allowing or disallowing information flows based on changing conditions or mission/operational considerations. Changing conditions include, for example, changes in organizational risk tolerance due to changes in the immediacy of mission/business needs, changes in the threat environment, and detection of potentially harmful or adverse events. Related control: SI-4.

>Tailoring Guidance

This security control/enhancement specifies a very specialized and/or advanced capability that is not required for all systems. Consequently, inclusion in a departmental profile is made on a case by case basis.

Ask AI

Configure your API key to use AI features.