← AC-16

Dynamic Attribute Association

LOW MODERATE HIGH
0 Overlays 0 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Dynamically associate security and privacy attributes with [organization-defined subjects and objects] in accordance with the following security and privacy policies as information is created and combined: [organization-defined security and privacy policies].

Discussion (NIST Supplemental Guidance)

Dynamic association of attributes is appropriate whenever the security or privacy characteristics of information change over time. Attributes may change due to information aggregation issues (i.e., characteristics of individual data elements are different from the combined elements), changes in individual access authorizations (i.e., privileges), changes in the security category of information, or changes in security or privacy policies. Attributes may also change situationally.

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for AC-16(1) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. subjects with which security attributes are to be dynamically associated as information is created and combined are defined;
  2. objects with which security attributes are to be dynamically associated as information is created and combined are defined;
  3. subjects with which privacy attributes are to be dynamically associated as information is created and combined are defined;
  4. objects with which privacy attributes are to be dynamically associated as information is created and combined are defined;
  5. security policies requiring dynamic association of security attributes with subjects and objects are defined;
  6. privacy policies requiring dynamic association of privacy attributes with subjects and objects are defined;
  7. security attributes are dynamically associated with <AC-16(01)_ODP[01] subjects> in accordance with the following security policies as information is created and combined: <AC-16(01)_ODP[05] security policies>;
  8. security attributes are dynamically associated with <AC-16(01)_ODP[02] objects> in accordance with the following security policies as information is created and combined: <AC-16(01)_ODP[05] security policies>;
  9. privacy attributes are dynamically associated with <AC-16(01)_ODP[03] subjects> in accordance with the following privacy policies as information is created and combined: <AC-16(01)_ODP[06] privacy policies>;
  10. privacy attributes are dynamically associated with <AC-16(01)_ODP[04] objects> in accordance with the following privacy policies as information is created and combined: <AC-16(01)_ODP[06] privacy policies>.

Examine

[SELECT FROM: Access control policy; procedures addressing dynamic association of security and privacy attributes to information; system design documentation; system configuration settings and associated documentation; system audit records; system security plan; privacy plan; other relevant documents or records].

Interview

[SELECT FROM: System/network administrators; organizational personnel with information security and privacy responsibilities; system developers].

Test

[SELECT FROM: Automated mechanisms implementing dynamic association of security and privacy attributes to information].

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for AC-16(1). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • Access control policy
  • system security plan
  • privacy plan

Configuration

  • system design documentation
  • system configuration settings and associated documentation

Testing

  • Automated mechanisms implementing dynamic association of security and privacy attributes to information

Other Records

  • procedures addressing dynamic association of security and privacy attributes to information
  • system audit records
  • other relevant documents or records