← AC-16

Maintenance of Attribute Associations by System

LOW MODERATE HIGH
0 Overlays 0 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Maintain the association and integrity of [organization-defined security and privacy attributes] to [organization-defined subjects and objects].

Discussion (NIST Supplemental Guidance)

Maintaining the association and integrity of security and privacy attributes to subjects and objects with sufficient assurance helps to ensure that the attribute associations can be used as the basis of automated policy actions. The integrity of specific items, such as security configuration files, may be maintained through the use of an integrity monitoring mechanism that detects anomalies and changes that deviate from "known good" baselines. Automated policy actions include retention date expirations, access control decisions, information flow control decisions, and information disclosure decisions.

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for AC-16(3) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. security attributes that require association and integrity maintenance are defined;
  2. privacy attributes that require association and integrity maintenance are defined;
  3. subjects requiring the association and integrity of security attributes to such subjects to be maintained are defined;
  4. objects requiring the association and integrity of security attributes to such objects to be maintained are defined;
  5. subjects requiring the association and integrity of privacy attributes to such subjects to be maintained are defined;
  6. objects requiring the association and integrity of privacy attributes to such objects to be maintained are defined;
  7. the association and integrity of <AC-16(03)_ODP[01] security attributes> to <AC-16(03)_ODP[03] subjects> is maintained;
  8. the association and integrity of <AC-16(03)_ODP[01] security attributes> to <AC-16(03)_ODP[04] objects> is maintained.
  9. the association and integrity of <AC-16(03)_ODP[02] privacy attributes> to <AC-16(03)_ODP[05] subjects> is maintained;
  10. the association and integrity of <AC-16(03)_ODP[02] privacy attributes> to <AC-16(03)_ODP[06] objects> is maintained.

Examine

[SELECT FROM: Access control policy; procedures addressing the association of security and privacy attributes to information; procedures addressing labeling or marking; system design documentation; system configuration settings and associated documentation; system security plan; privacy plan; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with information security and privacy responsibilities; system developers].

Test

[SELECT FROM: Mechanisms maintaining association and integrity of security and privacy attributes to information].

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for AC-16(3). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • Access control policy
  • system security plan
  • privacy plan

Configuration

  • system design documentation
  • system configuration settings and associated documentation

Testing

  • Mechanisms maintaining association and integrity of security and privacy attributes to information

Other Records

  • procedures addressing the association of security and privacy attributes to information
  • procedures addressing labeling or marking
  • other relevant documents or records