AC-16 Security and Privacy Attributes. Provide the means to associate [organization-defined] with [organization-defined] for information in storage, in process, and/or in transmission; Ensure that the attribute associations are made and retained with the information; Establish
Security and Privacy Attributes. Provide the means to associate [organization-defined] with [organization-defined] for information in storage, in process, and/or in transmission; Ensure that the attribute associations ar.
5
artefacts
1
held by a system
2
at each review
hard
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Evidence that attribute associations persist through transformation, export and transfer, not just at creation · Identity provider / directory
periodic reviewEvidence produced at each review
- Record of the authorised personnel or processes permitted to change an attribute value · Identity provider / directory
- Audit records of attribute changes showing who altered a value and when · Identity provider / directory
governing documentDocuments that govern the control
- Defined set of security and privacy attributes and the permitted values for each · Policy repository / GRC workspace
- Design documentation showing where attributes bind to information at rest, in process and in transit · Policy repository / GRC workspace
First move
Mostly documents and reviews. Pull the 1 system-held artefact from your Identity provider / directory on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Attributes applied at ingest and silently stripped when data is copied to a reporting store or extract
- Permitted value set undefined, so free text labels accumulate and no rule can act on them
- No audit of attribute change, so a downgrade from restricted to public leaves no trace
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetAC-14 Permitted actions without identification or authentication · AC-17 Remote access