Association of Attributes by Authorized Individuals
LOW MODERATE HIGHRequirements NIST SOURCE
Provide the capability to associate [organization-defined security and privacy attributes] with [organization-defined subjects and objects] by authorized individuals (or processes acting on behalf of individuals).
Discussion (NIST Supplemental Guidance)
Systems, in general, provide the capability for privileged users to assign security and privacy attributes to system-defined subjects (e.g., users) and objects (e.g., directories, files, and ports). Some systems provide additional capability for general users to assign security and privacy attributes to additional objects (e.g., files, emails). The association of attributes by authorized individuals is described in the design documentation. The support provided by systems can include prompting users to select security and privacy attributes to be associated with information objects, employing automated mechanisms to categorize information with attributes based on defined policies, or ensuring that the combination of the security or privacy attributes selected is valid. Organizations consider the creation, deletion, or modification of attributes when defining auditable events.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for AC-16(4) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- security attributes to be associated with subjects by authorized individuals (or processes acting on behalf of individuals) are defined;
- security attributes to be associated with objects by authorized individuals (or processes acting on behalf of individuals) are defined;
- privacy attributes to be associated with subjects by authorized individuals (or processes acting on behalf of individuals) are defined;
- privacy attributes to be associated with objects by authorized individuals (or processes acting on behalf of individuals) are defined;
- subjects requiring the association of security attributes by authorized individuals (or processes acting on behalf of individuals) are defined;
- objects requiring the association of security attributes by authorized individuals (or processes acting on behalf of individuals) are defined;
- subjects requiring the association of privacy attributes by authorized individuals (or processes acting on behalf of individuals) are defined;
- objects requiring the association of privacy attributes by authorized individuals (or processes acting on behalf of individuals) are defined;
- authorized individuals (or processes acting on behalf of individuals) are provided with the capability to associate <AC-16(04)_ODP[01] security attributes> with <AC-16(04)_ODP[05] subjects>;
- authorized individuals (or processes acting on behalf of individuals) are provided with the capability to associate <AC-16(04)_ODP[02] security attributes> with <AC-16(04)_ODP[06] objects>;
- authorized individuals (or processes acting on behalf of individuals) are provided with the capability to associate <AC-16(04)_ODP[03] privacy attributes> with <AC-16(04)_ODP[07] subjects>;
- authorized individuals (or processes acting on behalf of individuals) are provided with the capability to associate <AC-16(04)_ODP[04] privacy attributes> with <AC-16(04)_ODP[08] objects>.
Examine
[SELECT FROM: Access control policy; procedures addressing the association of security and privacy attributes to information; system design documentation; system configuration settings and associated documentation; list of users authorized to associate security and privacy attributes to information; system prompts for privileged users to select security and privacy attributes to be associated with information objects; system audit records; system security plan; privacy plan; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with responsibilities for associating security and privacy attributes to information; organizational personnel with information security and privacy responsibilities; system developers].
Test
[SELECT FROM: Mechanisms supporting user associations of security and privacy attributes to information].
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for AC-16(4). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- Access control policy
- system security plan
- privacy plan
Configuration
- system design documentation
- system configuration settings and associated documentation
Testing
- Mechanisms supporting user associations of security and privacy attributes to information
Other Records
- procedures addressing the association of security and privacy attributes to information
- list of users authorized to associate security and privacy attributes to information
- system prompts for privileged users to select security and privacy attributes to be associated with information objects
- system audit records
- other relevant documents or records