AC-4_information-flow-enforcement
Enforce approved authorizations for controlling the flow of information within the system and between connected systems based on [organization-defined
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Enforce approved authorizations for controlling the flow of information within the system and between connected systems based on [organization-defined
Identify and document [organization-defined] ;
Authorize access for [organization-defined] to: [organization-defined] ; and [organization-defined].
Require that users of system accounts (or roles) with access to [organization-defined] use non-privileged accounts or roles, when accessing nonsecurit
Authorize network access to [organization-defined] only for [organization-defined] and document the rationale for such access in the security plan for
Provide separate processing domains to enable finer-grained allocation of user privileges.
Restrict privileged accounts on the system to [organization-defined].
Prohibit privileged access to the system by non-organizational users.
Review [organization-defined] the privileges assigned to [organization-defined] to validate the need for such privileges;
Prevent the following software from executing at higher privilege levels than users executing the software: [organization-defined].