one-way information flow
An architectural security property of an information path between two systems or domains in which data is permitted to travel in only one direction — from source to destination — with no return channel possible. It distinguishes itself from general access control by regulating *where* data can travel rather than *who* may access it, making bidirectional communication structurally or physically impossible rather than merely policy-prohibited. Standards bodies such as NIST (SP 800-53 AC-4 and SP 800-171 3.1.3) cite it as an enforcement mechanism alongside write-permission verification and regrading, specifically "employing hardware mechanisms to enforce one-way information flows" — typically realized as a data diode or unidirectional security gateway — applied wherever networks of differing confidentiality or integrity must be separated, such as preventing back-channel exfiltration into classified networks or blocking malware ingress into high-integrity industrial control systems.
Framework senses
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- An architectural security property of an information path between two systems or domains in which data is permitted to travel in only one direction — from source to destination — with no return channel possible. It distinguishes itself from general access control by regulating *where* data can travel rather than *who* may access it, making bidirectional communication structurally or physically impossible rather than merely policy-prohibited. Standards bodies such as NIST (SP 800-53 AC-4 and SP 800-171 3.1.3) cite it as an enforcement mechanism alongside write-permission verification and regrading, specifically "employing hardware mechanisms to enforce one-way information flows" — typically realized as a data diode or unidirectional security gateway — applied wherever networks of differing confidentiality or integrity must be separated, such as preventing back-channel exfiltration into classified networks or blocking malware ingress into high-integrity industrial control systems.DR-088 backfill from the noun definition column