← Back to catalog
AC-4(19)
Validation of Metadata
Access Control (AC)
Baselines
Low · Not includedModerate · Not includedHigh · Not included
Description
When transferring information between different security domains, implement [assignment] on metadata.
Discussion
All information (including metadata and the data to which the metadata applies) is subject to filtering and inspection. Some organizations distinguish between metadata and data payloads (i.e., only the data to which the metadata is bound). Other organizations do not make such distinctions and consider metadata and the data to which the metadata applies to be part of the payload.
Implementation guidance
No content available.
CSF 2.0 crosswalk
No CSF mappings exist for this control.