AC-04(19) Validation of Metadata

When transferring information between different security domains, implement ac-4.19_prm_1 on metadata.

Parameter ID Definition
ac-4.19_prm_1 organization-defined security or privacy policy filters
ac-04.19_odp.01 security policy filters
ac-04.19_odp.02 privacy policy filters

Baselines

Guidance

All information (including metadata and the data to which the metadata applies) is subject to filtering and inspection. Some organizations distinguish between metadata and data payloads (i.e., only the data to which the metadata is bound). Other organizations do not make such distinctions and consider metadata and the data to which the metadata applies to be part of the payload.