Attribute Reassignment — Regrading Mechanisms
LOW MODERATE HIGHRequirements NIST SOURCE
Change security and privacy attributes associated with information only via regrading mechanisms validated using [organization-defined techniques or procedures].
Discussion (NIST Supplemental Guidance)
A regrading mechanism is a trusted process authorized to re-classify and re-label data in accordance with a defined policy exception. Validated regrading mechanisms are used by organizations to provide the requisite levels of assurance for attribute reassignment activities. The validation is facilitated by ensuring that regrading mechanisms are single purpose and of limited function. Since security and privacy attribute changes can directly affect policy enforcement actions, implementing trustworthy regrading mechanisms is necessary to help ensure that such mechanisms perform in a consistent and correct mode of operation.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for AC-16(9) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- techniques or procedures used to validate regrading mechanisms for security attributes are defined;
- techniques or procedures used to validate regrading mechanisms for privacy attributes are defined;
- security attributes associated with information are changed only via regrading mechanisms validated using <AC-16(09)_ODP[01] techniques or procedures>;
- privacy attributes associated with information are changed only via regrading mechanisms validated using <AC-16(09)_ODP[02] techniques or procedures>.
Examine
[SELECT FROM: Access control policy; procedures addressing reassignment of security attributes to information; system design documentation; system configuration settings and associated documentation; system audit records; system security plan; privacy plan; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with responsibilities for reassigning association of security and privacy attributes to information; organizational personnel with information security and privacy responsibilities; system developers].
Test
[SELECT FROM: Mechanisms implementing techniques or procedures for reassigning association of security and privacy attributes to information].
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for AC-16(9). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- Access control policy
- system security plan
- privacy plan
Configuration
- system design documentation
- system configuration settings and associated documentation
Testing
- Mechanisms implementing techniques or procedures for reassigning association of security and privacy attributes to information
Other Records
- procedures addressing reassignment of security attributes to information
- system audit records
- other relevant documents or records