AC-04(13) Decomposition into Policy-relevant Subcomponents
When transferring information between different security domains, decompose information into ac-04.13_odp for submission to policy enforcement mechanisms.
Parameter ID | Definition |
---|---|
ac-04.13_odp | policy-relevant subcomponents |
Baselines
- L
- M
- H
- P
Guidance
Decomposing information into policy-relevant subcomponents prior to information transfer facilitates policy decisions on source, destination, certificates, classification, attachments, and other security- or privacy-related component differentiators. Policy enforcement mechanisms apply filtering, inspection, and/or sanitization rules to the policy-relevant subcomponents of information to facilitate flow enforcement prior to transferring such information to different security domains.