designated source
An endpoint — a network, individual, or device — that has been explicitly authorized and named in an information flow control policy as a permitted origin of information movement within or between systems, distinct from *who* may access the information. Flow control policies operate on the characteristics of the information or the information path, and enforcement is carried out in boundary protection devices such as firewalls, routers, and gateways that apply rule sets or packet- and message-filtering capabilities. In practice, organizations use information flow control policies and enforcement mechanisms to govern the movement of sensitive data (e.g., CUI) between designated sources and destinations, regulating *where* information may travel rather than merely *who* may see it. The expression is strictly paired — a source has meaning only relative to a corresponding destination — and the "designated" qualifier signals that the endpoint has been deliberately enumerated in policy, not simply inferred at runtime.
Framework senses
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- An endpoint — a network, individual, or device — that has been explicitly authorized and named in an information flow control policy as a permitted origin of information movement within or between systems, distinct from *who* may access the information. Flow control policies operate on the characteristics of the information or the information path, and enforcement is carried out in boundary protection devices such as firewalls, routers, and gateways that apply rule sets or packet- and message-filtering capabilities. In practice, organizations use information flow control policies and enforcement mechanisms to govern the movement of sensitive data (e.g., CUI) between designated sources and destinations, regulating *where* information may travel rather than merely *who* may see it. The expression is strictly paired — a source has meaning only relative to a corresponding destination — and the "designated" qualifier signals that the endpoint has been deliberately enumerated in policy, not simply inferred at runtime.DR-088 backfill from the noun definition column