AC-04(02) Processing Domains
Use protected processing domains to enforce ac-04.02_odp as a basis for flow control decisions.
|ac-04.02_odp||information flow control policies|
Protected processing domains within systems are processing spaces that have controlled interactions with other processing spaces, enabling control of information flows between these spaces and to/from information objects. A protected processing domain can be provided, for example, by implementing domain and type enforcement. In domain and type enforcement, system processes are assigned to domains, information is identified by types, and information flows are controlled based on allowed information accesses (i.e., determined by domain and type), allowed signaling among domains, and allowed process transitions to other domains.
Related controls 1
- SC-39 Process Isolation L M H P