STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← All Controls

AC-4 (17)

Access ControlRev 5system

Domain Authentication

Control Statement

Uniquely identify and authenticate source and destination points by [Selection: organization-defined value] for information transfer.

Supplemental Guidance

Attribution is a critical component of a security and privacy concept of operations. The ability to identify source and destination points for information flowing within systems allows the forensic reconstruction of events and encourages policy compliance by attributing policy violations to specific organizations or individuals. Successful domain authentication requires that system labels distinguish among systems, organizations, and individuals involved in preparing, sending, receiving, or disseminating information. Attribution also allows organizations to better maintain the lineage of personally identifiable information processing as it flows through systems and can facilitate consent tracking, as well as correction, deletion, or access requests from individuals.

Related Controls (3)

IA-2IA-3IA-9

CCI Identifiers (11)

CCI-000223The information system binds security attributes to information to facilitate information flow policy enforcement.CCI-000224The information system tracks problems associated with the security attribute binding.CCI-002205Uniquely identify and authenticate source by organization, system, application, service, and/or individual for information transfer.CCI-002206The information system uniquely authenticates source by organization, system, application, and/or individual for information transfer.deprecatedCCI-002207Uniquely identify and authenticate destination points by organization, system, application, service, and/or individual for information transfer.CCI-002208The information system uniquely authenticates destination by organization, system, application, and/or individual for information transfer.deprecatedCCI-001377The information system uniquely authenticates source domains for information transfer.CCI-001555The information system uniquely identifies destination domains for information transfer.CCI-001556The information system uniquely authenticates destination domains for information transfer.CCI-001557The information system tracks problems associated with the information transfer.CCI-001376The information system uniquely identifies source domains for information transfer.

Linked STIG Checks (39)

Across 21 STIGs. Click to expand.