document characteristic
An observable, inspectable property or set of properties of a file or message — such as file type, format structure, embedded metadata, keyword patterns, classification markings, or fingerprint signatures — that a security control can evaluate without necessarily reading the full semantic content. It is the document-level analogue of packet-header attributes: just as a firewall can filter on header fields, a boundary protection device or DLP engine can filter on document-level signals to make allow/block/redirect decisions. In practice, NIST SP 800-171r3 places it alongside keyword searches as one of the mechanisms by which boundary protection devices provide a "message-filtering capability based on message content," with organizations also evaluating the trustworthiness of the filtering and inspection mechanisms themselves that are critical to information flow enforcement. The term is compositional in grammar but functions as a recognized technical shorthand in information-flow and content-inspection contexts, where flow control is based on characteristics of the information or the information path.
Framework senses
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- An observable, inspectable property or set of properties of a file or message — such as file type, format structure, embedded metadata, keyword patterns, classification markings, or fingerprint signatures — that a security control can evaluate without necessarily reading the full semantic content. It is the document-level analogue of packet-header attributes: just as a firewall can filter on header fields, a boundary protection device or DLP engine can filter on document-level signals to make allow/block/redirect decisions. In practice, NIST SP 800-171r3 places it alongside keyword searches as one of the mechanisms by which boundary protection devices provide a "message-filtering capability based on message content," with organizations also evaluating the trustworthiness of the filtering and inspection mechanisms themselves that are critical to information flow enforcement. The term is compositional in grammar but functions as a recognized technical shorthand in information-flow and content-inspection contexts, where flow control is based on characteristics of the information or the information path.DR-088 backfill from the noun definition column