Rule ID
SV-288264r1252959_rule
Version
V1R0.1
If the application does not dynamically reconfigure the data security attributes as data is created and combined, there is the possibility that the security attributes will not correctly reflect the data with which they are associated. Security attributes are abstractions representing the basic properties or characteristics of an entity (e.g., subjects and objects) with respect to safeguarding information. These attributes are typically associated with internal data structures (e.g., data records, buffers, files) within the application and are used to enable the implementation of access control and flow control policies, reflect special dissemination, handling, or distribution instructions, or support other aspects of the information security policy. Organizations define the security attributes of their data (e.g., classified, CUI). When data is created and/or combined, data security attributes defined by organizational policy must be dynamically created and/or updated to reflect the potential change in data sensitivity and characteristics. Dynamic association of security attributes is appropriate whenever the security characteristics of information changes over time. Security attributes may change, for example, due to information aggregation issues (i.e., the security characteristics of individual information elements are different from the combined elements), changes in individual access authorizations (i.e., privileges), and changes in the security category of information. This requirement pertains to Zero Trust.
Review the application documentation and deployed configuration to determine whether the application dynamically associates security attributes with organization-defined subjects in accordance with organization-defined security policies as information is created and combined. If the application does not dynamically associate security attributes with organization-defined subjects in accordance with organization-defined security policies as information is created and combined, this is a finding.
Configure the application to dynamically associate security attributes with organization-defined subjects in accordance with organization-defined security policies as information is created and combined.