AC-4(19): Validation of Metadata
Control Family:
Parent Control:
Threats Addressed:
Baselines:
(Not part of any baseline)
Previous Version:
- NIST Special Publication 800-53 Revision 4:
- AC-4(19): Validation Of Metadata
Control Statement
When transferring information between different security domains, implement [Assignment: organization-defined security or privacy policy filters] on metadata.
Supplemental Guidance
All information (including metadata and the data to which the metadata applies) is subject to filtering and inspection. Some organizations distinguish between metadata and data payloads (i.e., only the data to which the metadata is bound). Other organizations do not make such distinctions and consider metadata and the data to which the metadata applies to be part of the payload.