agreement that specifies how the information flow is enforced
A formal, documented commitment between two or more organizations — typically an interconnection security agreement (ISA), memorandum of understanding/agreement (MOU/MOA), or data-sharing contract — whose specific purpose is to articulate the technical and policy rules that govern *how* data is permitted to move across an organizational or security-domain boundary and how those rules are actively implemented and verified. Information flow control regulates where information can travel within a system and between systems — in contrast to who is allowed to access the information — and without regard to subsequent accesses to that information. Such an agreement is invoked precisely when two parties operate under different security or privacy policies, because transferring information between systems in different security or privacy domains with different security or privacy policies introduces the risk that such transfers violate one or more domain security or privacy policies. In practice, enforcement includes prohibiting information transfers between connected systems, verifying write permissions before accepting information from another security or privacy domain, employing hardwar
Framework senses
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A formal, documented commitment between two or more organizations — typically an interconnection security agreement (ISA), memorandum of understanding/agreement (MOU/MOA), or data-sharing contract — whose specific purpose is to articulate the technical and policy rules that govern *how* data is permitted to move across an organizational or security-domain boundary and how those rules are actively implemented and verified. Information flow control regulates where information can travel within a system and between systems — in contrast to who is allowed to access the information — and without regard to subsequent accesses to that information. Such an agreement is invoked precisely when two parties operate under different security or privacy policies, because transferring information between systems in different security or privacy domains with different security or privacy policies introduces the risk that such transfers violate one or more domain security or privacy policies. In practice, enforcement includes prohibiting information transfers between connected systems, verifying write permissions before accepting information from another security or privacy domain, employing hardwarDR-088 backfill from the noun definition column