Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, and individual lessons.

NIST SP 800-53 Learning Center

AC-16 — Security and Privacy Attributes

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

10Enhancements
17Parameters
0Baseline memberships
3Assessment methods

AC — Access Control · NIST SP 800-53 Release 5.2.0

Official NIST control content

Control statement

  1. a.Provide the means to associate [Organization-defined: organization-defined types of security and privacy attributes] with [Organization-defined: organization-defined security and privacy attribute values] for information in storage, in process, and/or in transmission;
  2. b.Ensure that the attribute associations are made and retained with the information;
  3. c.Establish the following permitted security and privacy attributes from the attributes defined in [AC-16a](#ac-16_smt.a) for [Organization-defined: organization-defined systems]: [Organization-defined: organization-defined security and privacy attributes];
  4. d.Determine the following permitted attribute values or ranges for each of the established attributes: [Organization-defined: attribute values or ranges];
  5. e.Audit changes to attributes; and
  6. f.Review [Organization-defined: organization-defined security and privacy attributes] for applicability [Organization-defined: organization-defined frequency].
Official NIST discussion

Discussion

Information is represented internally within systems using abstractions known as data structures. Internal data structures can represent different types of entities, both active and passive. Active entities, also known as subjects, are typically associated with individuals, devices, or processes acting on behalf of individuals. Passive entities, also known as objects, are typically associated with data structures, such as records, buffers, tables, files, inter-process pipes, and communications ports. Security attributes, a form of metadata, are abstractions that represent the basic properties or characteristics of active and passive entities with respect to safeguarding information. Privacy attributes, which may be used independently or in conjunction with security attributes, represent the basic properties or characteristics of active or passive entities with respect to the management of personally identifiable information. Attributes can be either explicitly or implicitly associated with the information contained in organizational systems or system components. Attributes may be associated with active entities (i.e., subjects) that have the potential to send or receive information, cause information to flow among objects, or change the system state. These attributes may also be associated with passive entities (i.e., objects) that contain or receive information. The association of attributes to subjects and objects by a system is referred to as binding and is inclusive of setting the attribute value and the attribute type. Attributes, when bound to data or information, permit the enforcement of security and privacy policies for access control and information flow control, including data retention limits, permitted uses of personally identifiable information, and identification of personal information within data objects. Such enforcement occurs through organizational processes or system functions or mechanisms. The binding techniques implemented by systems affect the strength of attribute binding to information. Binding strength and the assurance associated with binding techniques play important parts in the trust that organizations have in the information flow enforcement process. The binding techniques affect the number and degree of additional reviews required by organizations. The content or assigned values of attributes can directly affect the ability of individuals to access organizational information. Organizations can define the types of attributes needed for systems to support missions or business functions. There are many values that can be assigned to a security attribute. By specifying the permitted attribute ranges and values, organizations ensure that attribute values are meaningful and relevant. Labeling refers to the association of attributes with the subjects and objects represented by the internal data structures within systems. This facilitates system-based enforcement of information security and privacy policies. Labels include classification of information in accordance with legal and compliance requirements (e.g., top secret, secret, confidential, controlled unclassified), information impact level; high value asset information, access authorizations, nationality; data life cycle protection (i.e., encryption and data expiration), personally identifiable information processing permissions, including individual consent to personally identifiable information processing, and contractor affiliation. A related term to labeling is marking. Marking refers to the association of attributes with objects in a human-readable form and displayed on system media. Marking enables manual, procedural, or process-based enforcement of information security and privacy policies. Security and privacy labels may have the same value as media markings (e.g., top secret, secret, confidential). See [MP-3](#mp-3) (Media Marking).

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

organization-defined types of security and privacy attributes
organization-defined security and privacy attribute values
organization-defined systems
organization-defined security and privacy attributes
organization-defined security and privacy attributes
organization-defined frequency
types of security attributestypes of security attributes to be associated with information security attribute values for information in storage, in process, and/or in transmission are defined;
types of privacy attributestypes of privacy attributes to be associated with privacy attribute values for information in storage, in process, and/or in transmission are defined;
security attribute valuessecurity attribute values for types of security attributes are defined;
privacy attribute valuesprivacy attribute values for types of privacy attributes are defined;
systemssystems for which permitted security attributes are to be established are defined;
systemssystems for which permitted privacy attributes are to be established are defined;
security attributessecurity attributes defined as part of AC-16a that are permitted for systems are defined;
privacy attributesprivacy attributes defined as part of AC-16a that are permitted for systems are defined;
attribute values or rangesattribute values or ranges for established attributes are defined;
frequencythe frequency at which to review security attributes for applicability is defined;
frequencythe frequency at which to review privacy attributes for applicability is defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Security and Privacy Attributes as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to identity, authorization, least privilege, session boundaries, and access lifecycle governance.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • access approvals and entitlement records
  • role and group configuration exports
  • periodic access review results
  • authentication and authorization logs

Common failure patterns

  • standing privileges that outlive business need
  • shared or orphaned accounts
  • access rules implemented differently across systems
  • approvals that cannot be traced to actual permissions

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. AC-16a.
    1. AC-16a.[01]the means to associate [Organization-defined: types of security attributes] with [Organization-defined: security attribute values] for information in storage, in process, and/or in transmission are provided;
    2. AC-16a.[02]the means to associate [Organization-defined: types of privacy attributes] with [Organization-defined: privacy attribute values] for information in storage, in process, and/or in transmission are provided;
  2. AC-16b.
    1. AC-16b.[01]attribute associations are made;
    2. AC-16b.[02]attribute associations are retained with the information;
  3. AC-16c.
    1. AC-16c.[01]the following permitted security attributes are established from the attributes defined in AC-16_ODP[01] for [Organization-defined: systems]: [Organization-defined: security attributes];
    2. AC-16c.[02]the following permitted privacy attributes are established from the attributes defined in AC-16_ODP[02] for [Organization-defined: systems]: [Organization-defined: privacy attributes];
  4. AC-16d.the following permitted attribute values or ranges for each of the established attributes are determined: [Organization-defined: attribute values or ranges];
  5. AC-16e.changes to attributes are audited;
  6. AC-16f.
    1. AC-16f.[01][Organization-defined: security attributes] are reviewed for applicability [Organization-defined: frequency];
    2. AC-16f.[02][Organization-defined: privacy attributes] are reviewed for applicability [Organization-defined: frequency].

Examine

  • Access control policy
  • procedures addressing the association of security and privacy attributes to information in storage, in process, and in transmission
  • system design documentation
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security and privacy responsibilities
  • system developers

Test

  • Organizational capability supporting and maintaining the association of security and privacy attributes to information in storage, in process, and in transmission
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

AC-16(1) — Dynamic Attribute Association

Dynamically associate security and privacy attributes with [Organization-defined: organization-defined subjects and objects] in accordance with the following security and privacy policies as information is created and combined: [Organization-defined: organization-defined security and privacy policies].

Official discussion

Dynamic association of attributes is appropriate whenever the security or privacy characteristics of information change over time. Attributes may change due to information aggregation issues (i.e., characteristics of individual data elements are different from the combined elements), changes in individual access authorizations (i.e., privileges), changes in the security category of information, or changes in security or privacy policies. Attributes may also change situationally.

Organization-defined parameters (8)
organization-defined subjects and objects
organization-defined security and privacy policies
subjectssubjects with which security attributes are to be dynamically associated as information is created and combined are defined;
objectsobjects with which security attributes are to be dynamically associated as information is created and combined are defined;
subjectssubjects with which privacy attributes are to be dynamically associated as information is created and combined are defined;
objectsobjects with which privacy attributes are to be dynamically associated as information is created and combined are defined;
security policiessecurity policies requiring dynamic association of security attributes with subjects and objects are defined;
privacy policiesprivacy policies requiring dynamic association of privacy attributes with subjects and objects are defined;
Assessment objectives and methods
  1. AC-16(01)[01]security attributes are dynamically associated with [Organization-defined: subjects] in accordance with the following security policies as information is created and combined: [Organization-defined: security policies];
  2. AC-16(01)[02]security attributes are dynamically associated with [Organization-defined: objects] in accordance with the following security policies as information is created and combined: [Organization-defined: security policies];
  3. AC-16(01)[03]privacy attributes are dynamically associated with [Organization-defined: subjects] in accordance with the following privacy policies as information is created and combined: [Organization-defined: privacy policies];
  4. AC-16(01)[04]privacy attributes are dynamically associated with [Organization-defined: objects] in accordance with the following privacy policies as information is created and combined: [Organization-defined: privacy policies].

Examine

  • Access control policy
  • procedures addressing dynamic association of security and privacy attributes to information
  • system design documentation
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security and privacy responsibilities
  • system developers

Test

  • Automated mechanisms implementing dynamic association of security and privacy attributes to information
Official NIST control enhancement

AC-16(2) — Attribute Value Changes by Authorized Individuals

Provide authorized individuals (or processes acting on behalf of individuals) the capability to define or change the value of associated security and privacy attributes.

Official discussion

The content or assigned values of attributes can directly affect the ability of individuals to access organizational information. Therefore, it is important for systems to be able to limit the ability to create or modify attributes to authorized individuals.

Assessment objectives and methods
  1. AC-16(02)[01]authorized individuals (or processes acting on behalf of individuals) are provided with the capability to define or change the value of associated security attributes;
  2. AC-16(02)[02]authorized individuals (or processes acting on behalf of individuals) are provided with the capability to define or change the value of associated privacy attributes.

Examine

  • Access control policy
  • procedures addressing the change of security and privacy attribute values
  • system design documentation
  • system configuration settings and associated documentation
  • list of individuals authorized to change security and privacy attributes
  • system audit records
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with responsibilities for changing values of security and privacy attributes
  • organizational personnel with information security and privacy responsibilities
  • system developers

Test

  • Mechanisms permitting changes to values of security and privacy attributes
Official NIST control enhancement

AC-16(3) — Maintenance of Attribute Associations by System

Maintain the association and integrity of [Organization-defined: organization-defined security and privacy attributes] to [Organization-defined: organization-defined subjects and objects].

Official discussion

Maintaining the association and integrity of security and privacy attributes to subjects and objects with sufficient assurance helps to ensure that the attribute associations can be used as the basis of automated policy actions. The integrity of specific items, such as security configuration files, may be maintained through the use of an integrity monitoring mechanism that detects anomalies and changes that deviate from "known good" baselines. Automated policy actions include retention date expirations, access control decisions, information flow control decisions, and information disclosure decisions.

Organization-defined parameters (8)
organization-defined security and privacy attributes
organization-defined subjects and objects
security attributessecurity attributes that require association and integrity maintenance are defined;
privacy attributesprivacy attributes that require association and integrity maintenance are defined;
subjectssubjects requiring the association and integrity of security attributes to such subjects to be maintained are defined;
objectsobjects requiring the association and integrity of security attributes to such objects to be maintained are defined;
subjectssubjects requiring the association and integrity of privacy attributes to such subjects to be maintained are defined;
objectsobjects requiring the association and integrity of privacy attributes to such objects to be maintained are defined;
Assessment objectives and methods
  1. AC-16(03)[01]the association and integrity of [Organization-defined: security attributes] to [Organization-defined: subjects] is maintained;
  2. AC-16(03)[02]the association and integrity of [Organization-defined: security attributes] to [Organization-defined: objects] is maintained.
  3. AC-16(03)[03]the association and integrity of [Organization-defined: privacy attributes] to [Organization-defined: subjects] is maintained;
  4. AC-16(03)[04]the association and integrity of [Organization-defined: privacy attributes] to [Organization-defined: objects] is maintained.

Examine

  • Access control policy
  • procedures addressing the association of security and privacy attributes to information
  • procedures addressing labeling or marking
  • system design documentation
  • system configuration settings and associated documentation
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with information security and privacy responsibilities
  • system developers

Test

  • Mechanisms maintaining association and integrity of security and privacy attributes to information
Official NIST control enhancement

AC-16(4) — Association of Attributes by Authorized Individuals

Provide the capability to associate [Organization-defined: organization-defined security and privacy attributes] with [Organization-defined: organization-defined subjects and objects] by authorized individuals (or processes acting on behalf of individuals).

Official discussion

Systems, in general, provide the capability for privileged users to assign security and privacy attributes to system-defined subjects (e.g., users) and objects (e.g., directories, files, and ports). Some systems provide additional capability for general users to assign security and privacy attributes to additional objects (e.g., files, emails). The association of attributes by authorized individuals is described in the design documentation. The support provided by systems can include prompting users to select security and privacy attributes to be associated with information objects, employing automated mechanisms to categorize information with attributes based on defined policies, or ensuring that the combination of the security or privacy attributes selected is valid. Organizations consider the creation, deletion, or modification of attributes when defining auditable events.

Organization-defined parameters (10)
organization-defined security and privacy attributes
organization-defined subjects and objects
security attributessecurity attributes to be associated with subjects by authorized individuals (or processes acting on behalf of individuals) are defined;
security attributessecurity attributes to be associated with objects by authorized individuals (or processes acting on behalf of individuals) are defined;
privacy attributesprivacy attributes to be associated with subjects by authorized individuals (or processes acting on behalf of individuals) are defined;
privacy attributesprivacy attributes to be associated with objects by authorized individuals (or processes acting on behalf of individuals) are defined;
subjectssubjects requiring the association of security attributes by authorized individuals (or processes acting on behalf of individuals) are defined;
objectsobjects requiring the association of security attributes by authorized individuals (or processes acting on behalf of individuals) are defined;
subjectssubjects requiring the association of privacy attributes by authorized individuals (or processes acting on behalf of individuals) are defined;
objectsobjects requiring the association of privacy attributes by authorized individuals (or processes acting on behalf of individuals) are defined;
Assessment objectives and methods
  1. AC-16(04)[01]authorized individuals (or processes acting on behalf of individuals) are provided with the capability to associate [Organization-defined: security attributes] with [Organization-defined: subjects];
  2. AC-16(04)[02]authorized individuals (or processes acting on behalf of individuals) are provided with the capability to associate [Organization-defined: security attributes] with [Organization-defined: objects];
  3. AC-16(04)[03]authorized individuals (or processes acting on behalf of individuals) are provided with the capability to associate [Organization-defined: privacy attributes] with [Organization-defined: subjects];
  4. AC-16(04)[04]authorized individuals (or processes acting on behalf of individuals) are provided with the capability to associate [Organization-defined: privacy attributes] with [Organization-defined: objects].

Examine

  • Access control policy
  • procedures addressing the association of security and privacy attributes to information
  • system design documentation
  • system configuration settings and associated documentation
  • list of users authorized to associate security and privacy attributes to information
  • system prompts for privileged users to select security and privacy attributes to be associated with information objects
  • system audit records
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with responsibilities for associating security and privacy attributes to information
  • organizational personnel with information security and privacy responsibilities
  • system developers

Test

  • Mechanisms supporting user associations of security and privacy attributes to information
Official NIST control enhancement

AC-16(5) — Attribute Displays on Objects to Be Output

Display security and privacy attributes in human-readable form on each object that the system transmits to output devices to identify [Organization-defined: instructions] using [Organization-defined: naming conventions].

Official discussion

System outputs include printed pages, screens, or equivalent items. System output devices include printers, notebook computers, video displays, smart phones, and tablets. To mitigate the risk of unauthorized exposure of information (e.g., shoulder surfing), the outputs display full attribute values when unmasked by the subscriber.

Organization-defined parameters (2)
instructionsspecial dissemination, handling, or distribution instructions to be used for each object that the system transmits to output devices are defined;
naming conventionshuman-readable, standard naming conventions for the security and privacy attributes to be displayed in human-readable form on each object that the system transmits to output devices are defined;
Assessment objectives and methods
  1. AC-16(05)[01]security attributes are displayed in human-readable form on each object that the system transmits to output devices to identify [Organization-defined: instructions] using [Organization-defined: naming conventions];
  2. AC-16(05)[02]privacy attributes are displayed in human-readable form on each object that the system transmits to output devices to identify [Organization-defined: instructions] using [Organization-defined: naming conventions].

Examine

  • Access control policy
  • procedures addressing display of security and privacy attributes in human-readable form
  • special dissemination, handling, or distribution instructions
  • types of human-readable, standard naming conventions
  • system design documentation
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with information security and privacy responsibilities
  • system developers

Test

  • System output devices displaying security and privacy attributes in human-readable form on each object
Official NIST control enhancement

AC-16(6) — Maintenance of Attribute Association

Require personnel to associate and maintain the association of [Organization-defined: organization-defined security and privacy attributes] with [Organization-defined: organization-defined subjects and objects] in accordance with [Organization-defined: organization-defined security and privacy policies].

Official discussion

Maintaining attribute association requires individual users (as opposed to the system) to maintain associations of defined security and privacy attributes with subjects and objects.

Organization-defined parameters (13)
organization-defined security and privacy attributes
organization-defined subjects and objects
organization-defined security and privacy policies
security attributessecurity attributes to be associated with subjects are defined;
security attributessecurity attributes to be associated with objects are defined;
privacy attributesprivacy attributes to be associated with subjects are defined;
privacy attributesprivacy attributes to be associated with objects are defined;
subjectssubjects to be associated with information security attributes are defined;
objectsobjects to be associated with information security attributes are defined;
subjectssubjects to be associated with privacy attributes are defined;
objectsobjects to be associated with privacy attributes are defined;
security policiessecurity policies that require personnel to associate and maintain the association of security and privacy attributes with subjects and objects;
privacy policiesprivacy policies that require personnel to associate and maintain the association of security and privacy attributes with subjects and objects;
Assessment objectives and methods
  1. AC-16(06)[01]personnel are required to associate and maintain the association of [Organization-defined: security attributes] with [Organization-defined: subjects] in accordance with [Organization-defined: security policies];
  2. AC-16(06)[02]personnel are required to associate and maintain the association of [Organization-defined: security attributes] with [Organization-defined: objects] in accordance with [Organization-defined: security policies];
  3. AC-16(06)[03]personnel are required to associate and maintain the association of [Organization-defined: privacy attributes] with [Organization-defined: subjects] in accordance with [Organization-defined: privacy policies];
  4. AC-16(06)[04]personnel are required to associate and maintain the association of [Organization-defined: privacy attributes] with [Organization-defined: objects] in accordance with [Organization-defined: privacy policies].

Examine

  • Access control policy
  • procedures addressing association of security and privacy attributes with subjects and objects
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with responsibilities for associating and maintaining association of security and privacy attributes with subjects and objects
  • organizational personnel with information security and privacy responsibilities
  • system developers

Test

  • Mechanisms supporting associations of security and privacy attributes to subjects and objects
Official NIST control enhancement

AC-16(7) — Consistent Attribute Interpretation

Provide a consistent interpretation of security and privacy attributes transmitted between distributed system components.

Official discussion

To enforce security and privacy policies across multiple system components in distributed systems, organizations provide a consistent interpretation of security and privacy attributes employed in access enforcement and flow enforcement decisions. Organizations can establish agreements and processes to help ensure that distributed system components implement attributes with consistent interpretations in automated access enforcement and flow enforcement actions.

Assessment objectives and methods
  1. AC-16(07)[01]a consistent interpretation of security attributes transmitted between distributed system components is provided;
  2. AC-16(07)[02]a consistent interpretation of privacy attributes transmitted between distributed system components is provided.

Examine

  • Access control policies and procedures
  • procedures addressing consistent interpretation of security and privacy attributes transmitted between distributed system components
  • procedures addressing access enforcement
  • procedures addressing information flow enforcement
  • system design documentation
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • privacy access control policy
  • other relevant documents or records

Interview

  • Organizational personnel with responsibilities for providing consistent interpretation of security and privacy attributes used in access enforcement and information flow enforcement actions
  • organizational personnel with information security and privacy responsibilities
  • system developers

Test

  • Mechanisms implementing access enforcement and information flow enforcement functions
Official NIST control enhancement

AC-16(8) — Association Techniques and Technologies

Implement [Organization-defined: organization-defined techniques and technologies] in associating security and privacy attributes to information.

Official discussion

The association of security and privacy attributes to information within systems is important for conducting automated access enforcement and flow enforcement actions. The association of such attributes to information (i.e., binding) can be accomplished with technologies and techniques that provide different levels of assurance. For example, systems can cryptographically bind attributes to information using digital signatures that support cryptographic keys protected by hardware devices (sometimes known as hardware roots of trust).

Organization-defined parameters (3)
organization-defined techniques and technologies
techniques and technologiestechniques and technologies to be implemented in associating security attributes to information are defined;
techniques and technologiestechniques and technologies to be implemented in associating privacy attributes to information are defined;
Assessment objectives and methods
  1. AC-16(08)[01][Organization-defined: techniques and technologies] are implemented in associating security attributes to information;
  2. AC-16(08)[02][Organization-defined: techniques and technologies] are implemented in associating privacy attributes to information.

Examine

  • Access control policy
  • procedures addressing association of security and privacy attributes to information
  • system design documentation
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with responsibilities for associating security and privacy attributes to information
  • organizational personnel with information security and privacy responsibilities
  • system developers

Test

  • Mechanisms implementing techniques or technologies associating security and privacy attributes to information
Related controls
Official NIST control enhancement

AC-16(9) — Attribute Reassignment — Regrading Mechanisms

Change security and privacy attributes associated with information only via regrading mechanisms validated using [Organization-defined: organization-defined techniques or procedures].

Official discussion

A regrading mechanism is a trusted process authorized to re-classify and re-label data in accordance with a defined policy exception. Validated regrading mechanisms are used by organizations to provide the requisite levels of assurance for attribute reassignment activities. The validation is facilitated by ensuring that regrading mechanisms are single purpose and of limited function. Since security and privacy attribute changes can directly affect policy enforcement actions, implementing trustworthy regrading mechanisms is necessary to help ensure that such mechanisms perform in a consistent and correct mode of operation.

Organization-defined parameters (3)
organization-defined techniques or procedures
techniques or procedurestechniques or procedures used to validate regrading mechanisms for security attributes are defined;
techniques or procedurestechniques or procedures used to validate regrading mechanisms for privacy attributes are defined;
Assessment objectives and methods
  1. AC-16(09)[01]security attributes associated with information are changed only via regrading mechanisms validated using [Organization-defined: techniques or procedures];
  2. AC-16(09)[02]privacy attributes associated with information are changed only via regrading mechanisms validated using [Organization-defined: techniques or procedures].

Examine

  • Access control policy
  • procedures addressing reassignment of security attributes to information
  • system design documentation
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with responsibilities for reassigning association of security and privacy attributes to information
  • organizational personnel with information security and privacy responsibilities
  • system developers

Test

  • Mechanisms implementing techniques or procedures for reassigning association of security and privacy attributes to information
Official NIST control enhancement

AC-16(10) — Attribute Configuration by Authorized Individuals

Provide authorized individuals the capability to define or change the type and value of security and privacy attributes available for association with subjects and objects.

Official discussion

The content or assigned values of security and privacy attributes can directly affect the ability of individuals to access organizational information. Thus, it is important for systems to be able to limit the ability to create or modify the type and value of attributes available for association with subjects and objects to authorized individuals only.

Assessment objectives and methods
  1. AC-16(10)[01]authorized individuals are provided with the capability to define or change the type and value of security attributes available for association with subjects and objects;
  2. AC-16(10)[02]authorized individuals are provided with the capability to define or change the type and value of privacy attributes available for association with subjects and objects.

Examine

  • Access control policy
  • procedures addressing configuration of security and privacy attributes by authorized individuals
  • system design documentation
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with responsibilities for defining or changing security and privacy attributes associated with information
  • organizational personnel with information security and privacy responsibilities
  • system developers

Test

  • Mechanisms implementing capability for defining or changing security and privacy attributes
Source record

Authoritative sources