STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← All Controls

AC-4 (6)

Access ControlRev 5system

Information Flow Enforcement

Control Statement

Enforce information flow control based on [Assignment: metadata].

Supplemental Guidance

Metadata is information that describes the characteristics of data. Metadata can include structural metadata describing data structures or descriptive metadata describing data content. Enforcement of allowed information flows based on metadata enables simpler and more effective flow control. Organizations consider the trustworthiness of metadata regarding data accuracy (i.e., knowledge that the metadata values are correct with respect to the data), data integrity (i.e., protecting against unauthorized changes to metadata tags), and the binding of metadata to the data payload (i.e., employing sufficiently strong binding techniques with appropriate assurance).

Related Controls (2)

AC-16SI-7

CCI Identifiers (2)

CCI-000030Enforce information flow control based on organization-defined metadata.CCI-002194Defines the metadata the information system uses to enforce information flow control.

Linked STIG Checks (3)

Across 2 STIGs. Click to expand.