← Back to catalog
AC-16(10)

Attribute Configuration by Authorized Individuals

Access Control (AC)
Baselines
Low · Not includedModerate · Not includedHigh · Not included
Description

Provide authorized individuals the capability to define or change the type and value of security and privacy attributes available for association with subjects and objects.

Discussion

The content or assigned values of security and privacy attributes can directly affect the ability of individuals to access organizational information. Thus, it is important for systems to be able to limit the ability to create or modify the type and value of attributes available for association with subjects and objects to authorized individuals only.

Implementation guidance

No content available.

CSF 2.0 crosswalk

No CSF mappings exist for this control.