PlumbTrackLive demoGRC Risk System

← control library

Information Flow Enforcement AC-4

Access Control · Moderate baseline ✗ Not implemented

Status — program-wide

What references this control

No risks name this control in their Framework field yet.

No policies reference it yet.


Link a risk or policy to this control

Attaching adds AC-4 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.

Source: NIST SP 800-53 Rev.5, Access Control family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.

Control guide — plain-English, per NIST SP 800-53

AC-4 (Information Flow Enforcement) is about controlling where information is allowed to move — within the system and between it and connected systems — and enforcing those rules on purpose. Where AC-2 and AC-3 ask ‘who can log in and what can they touch,’ AC-4 asks ‘which traffic is allowed to flow, in which direction, to and from where.’ On a Linux lab server this is mostly a host-firewall job: you write down the approved flows and then make the box enforce exactly that. It is an Access Control that lives in the Moderate baseline (it is not selected at Low).

What good looks like

Framework mapping

How to move it toward Implemented