STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← All Controls

AC-16

Access ControlRev 5organization

Security and Privacy Attributes

Control Statement

a. Provide the means to associate [Assignment: organization-defined types of security and privacy attributes] with [Assignment: organization-defined security and privacy attribute values] for information in storage, in process, and/or in transmission; b. Ensure that the attribute associations are made and retained with the information; c. Establish the following permitted security and privacy attributes from the attributes defined in [AC-16a](#ac-16_smt.a) for [Assignment: organization-defined systems]: [Assignment: organization-defined security and privacy attributes]; d. Determine the following permitted attribute values or ranges for each of the established attributes: [Assignment: attribute values or ranges]; e. Audit changes to attributes; and f. Review [Assignment: organization-defined security and privacy attributes] for applicability [Assignment: organization-defined frequency].

Supplemental Guidance

Information is represented internally within systems using abstractions known as data structures. Internal data structures can represent different types of entities, both active and passive. Active entities, also known as subjects, are typically associated with individuals, devices, or processes acting on behalf of individuals. Passive entities, also known as objects, are typically associated with data structures, such as records, buffers, tables, files, inter-process pipes, and communications ports. Security attributes, a form of metadata, are abstractions that represent the basic properties or characteristics of active and passive entities with respect to safeguarding information. Privacy attributes, which may be used independently or in conjunction with security attributes, represent the basic properties or characteristics of active or passive entities with respect to the management of personally identifiable information. Attributes can be either explicitly or implicitly associated with the information contained in organizational systems or system components. Attributes may be associated with active entities (i.e., subjects) that have the potential to send or receive information, cause information to flow among objects, or change the system state. These attributes may also be associated with passive entities (i.e., objects) that contain or receive information. The association of attributes to subjects and objects by a system is referred to as binding and is inclusive of setting the attribute value and the attribute type. Attributes, when bound to data or information, permit the enforcement of security and privacy policies for access control and information flow control, including data retention limits, permitted uses of personally identifiable information, and identification of personal information within data objects. Such enforcement occurs through organizational processes or system functions or mechanisms. The binding techniques implemented by systems affect the strength of attribute binding to information. Binding strength and the assurance associated with binding techniques play important parts in the trust that organizations have in the information flow enforcement process. The binding techniques affect the number and degree of additional reviews required by organizations. The content or assigned values of attributes can directly affect the ability of individuals to access organizational information. Organizations can define the types of attributes needed for systems to support missions or business functions. There are many values that can be assigned to a security attribute. By specifying the permitted attribute ranges and values, organizations ensure that attribute values are meaningful and relevant. Labeling refers to the association of attributes with the subjects and objects represented by the internal data structures within systems. This facilitates system-based enforcement of information security and privacy policies. Labels include classification of information in accordance with legal and compliance requirements (e.g., top secret, secret, confidential, controlled unclassified), information impact level; high value asset information, access authorizations, nationality; data life cycle protection (i.e., encryption and data expiration), personally identifiable information processing permissions, including individual consent to personally identifiable information processing, and contractor affiliation. A related term to labeling is marking. Marking refers to the association of attributes with objects in a human-readable form and displayed on system media. Marking enables manual, procedural, or process-based enforcement of information security and privacy policies. Security and privacy labels may have the same value as media markings (e.g., top secret, secret, confidential). See [MP-3](#mp-3) (Media Marking).

Related Controls (16)

AC-3AC-4AC-6AC-21AC-25AU-2AU-10MP-3PE-22PT-2PT-3PT-4SC-11SC-16SI-12SI-18

CCI Identifiers (38)

CCI-002271Determine organization-defined attribute values or ranges for each of the established attributes.CCI-001396The organization defines security attributes for which the information system supports and maintains the bindings for information in storage.CCI-001397The organization defines security attributes for which the information system supports and maintains the bindings for information in process.CCI-002264Provide the means to associate organization-defined types of security attributes having organization-defined security attribute values with information in transmission.CCI-002265Ensure that the attribute associations are made and retained with the information.CCI-002266Ensure that the security attribute associations are retained with the information.CCI-002267Defines the security attributes that are permitted for organization-defined systems.CCI-002268Defines the systems for which permitted organization-defined attributes are to be established.

Linked STIG Checks (68)

Across 33 STIGs. Click to expand.

CCI-002270Defines the attribute values or ranges permitted for each of the established security attributes.
CCI-002262Provide the means to associate organization-defined types of security attributes having organization-defined security attribute values with information in storage.
CCI-003696Defines privacy attributes having organization-defined types of privacy attribute values which are associated with information in storage.
CCI-003697Defines privacy attributes having organization-defined types of privacy attribute values which are associated with information in process.
CCI-003698Defines privacy attributes, having organization-defined types of privacy attribute values, which are associated with information in transmission.
CCI-003699Defines privacy attribute values associated with organization-defined types of privacy attributes for information in storage.
CCI-003700Defines privacy attribute values associated with organization-defined types of privacy attributes for information in process.
CCI-003701Defines privacy attribute values associated with organization-defined types of privacy attributes for information in transmission.
CCI-003702Ensure that the privacy attribute associations are made with the information.
CCI-003703Ensure that the privacy attribute associations are restrained with the information.
CCI-003704Establish the following permitted organization-defined privacy attributes defined in AC-16a for organization-defined systems.
CCI-003706Defines the attribute values or ranges permitted for each of the established privacy attributes.
CCI-003707Audit changes to the attributes.
CCI-003708Review organization-defined security attributes for applicability on an organization-defined frequency.
CCI-003709Review organization-defined privacy attributes for applicability on an organization-defined frequency.
CCI-003710Defines the security and privacy attributes to be reviewed for applicability.
CCI-003711Defines the frequency of which the security and privacy attributes will be reviewed.
CCI-002256Defines security attributes having organization-defined types of security attribute values which are associated with information in storage.
CCI-002269Establish the following permitted organization-defined security attributes in AC-16a for organization-defined systems.
CCI-003705Defines the privacy attributes that are permitted for organization-defined systems.
CCI-002263Provide the means to associate organization-defined types of security attributes having organization-defined security attribute values with information in process.
CCI-001398The organization defines security attributes for which the information system supports and maintains the bindings for information in transmission.
CCI-001399The information system supports and maintains the binding of organization-defined security attributes to information in storage.
CCI-001400The information system supports and maintains the binding of organization-defined security attributes to information in process.
CCI-001401The information system supports and maintains the binding of organization-defined security attributes to information in transmission.
CCI-002257Defines security attributes having organization-defined types of security attribute values which are associated with information in process.
CCI-002258Defines security attributes, having organization-defined types of security attribute values, which are associated with information in transmission.
CCI-002259Defines security attribute values associated with organization-defined types of security attributes for information in storage.
CCI-002260Defines security attribute values associated with organization-defined types of security attributes for information in process.
CCI-002261Defines security attribute values associated with organization-defined types of security attributes for information in transmission.