STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← AC-4 (20) — Information Flow Enforcement

CCI-002213

Definition

Defines the information to be subjected to flow control across security domains.

Parent Control

AC-4 (20)Information Flow EnforcementAccess Control

Linked STIG Checks (4)

V-259890CAT IThe Enterprise Voice, Video, and Messaging Policy must define operations for VTC and endpoint cameras regarding the ability to pick up and transmit sensitive information.Enterprise Voice, Video, and Messaging Policy Security Requirements GuideV-259891CAT IIThe Enterprise Voice, Video, and Messaging Policy must define operations for endpoint microphones regarding the ability to pick up and transmit sensitive information.Enterprise Voice, Video, and Messaging Policy Security Requirements GuideV-259900CAT IIAn IP-based VTC system implementing a single set of input/output devices (cameras, microphones, speakers, control system), an A/V switcher, and multiple CODECs connected to multiple IP networks with different classification levels must provide automatic mutually exclusive power control for the CODECs or their network connections so only one CODEC is powered on or one CODEC is connected to any network at any given time.Enterprise Voice, Video, and Messaging Policy Security Requirements GuideV-259902CAT IIVideo conferencing, Unified Capability (UC) soft client, and speakerphone speaker operations policy must prevent disclosure of sensitive or classified information over nonsecure systems.Enterprise Voice, Video, and Messaging Policy Security Requirements Guide