Dynamic Attribute Association
LOW MODERATE HIGHRequirements NIST SOURCE
Dynamically associate security and privacy attributes with [organization-defined subjects and objects] in accordance with the following security and privacy policies as information is created and combined: [organization-defined security and privacy policies].
Discussion (NIST Supplemental Guidance)
Dynamic association of attributes is appropriate whenever the security or privacy characteristics of information change over time. Attributes may change due to information aggregation issues (i.e., characteristics of individual data elements are different from the combined elements), changes in individual access authorizations (i.e., privileges), changes in the security category of information, or changes in security or privacy policies. Attributes may also change situationally.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for AC-16(1) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- subjects with which security attributes are to be dynamically associated as information is created and combined are defined;
- objects with which security attributes are to be dynamically associated as information is created and combined are defined;
- subjects with which privacy attributes are to be dynamically associated as information is created and combined are defined;
- objects with which privacy attributes are to be dynamically associated as information is created and combined are defined;
- security policies requiring dynamic association of security attributes with subjects and objects are defined;
- privacy policies requiring dynamic association of privacy attributes with subjects and objects are defined;
- security attributes are dynamically associated with <AC-16(01)_ODP[01] subjects> in accordance with the following security policies as information is created and combined: <AC-16(01)_ODP[05] security policies>;
- security attributes are dynamically associated with <AC-16(01)_ODP[02] objects> in accordance with the following security policies as information is created and combined: <AC-16(01)_ODP[05] security policies>;
- privacy attributes are dynamically associated with <AC-16(01)_ODP[03] subjects> in accordance with the following privacy policies as information is created and combined: <AC-16(01)_ODP[06] privacy policies>;
- privacy attributes are dynamically associated with <AC-16(01)_ODP[04] objects> in accordance with the following privacy policies as information is created and combined: <AC-16(01)_ODP[06] privacy policies>.
Examine
[SELECT FROM: Access control policy; procedures addressing dynamic association of security and privacy attributes to information; system design documentation; system configuration settings and associated documentation; system audit records; system security plan; privacy plan; other relevant documents or records].
Interview
[SELECT FROM: System/network administrators; organizational personnel with information security and privacy responsibilities; system developers].
Test
[SELECT FROM: Automated mechanisms implementing dynamic association of security and privacy attributes to information].
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for AC-16(1). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- Access control policy
- system security plan
- privacy plan
Configuration
- system design documentation
- system configuration settings and associated documentation
Testing
- Automated mechanisms implementing dynamic association of security and privacy attributes to information
Other Records
- procedures addressing dynamic association of security and privacy attributes to information
- system audit records
- other relevant documents or records