home/glossary/information flow control policy

information flow control policy

nounverified·updated Aug 30, 2026

A security or privacy policy construct that specifies the authorized paths and directions along which data may move—within a system, between systems, or across security/privacy domains—based on the characteristics of the information itself or its path rather than on who holds access rights to it. It is distinct from access control policy in that it governs *where* information may travel rather than *who* may read it, and it is typically enforced at boundary devices (firewalls, guards, proxies, data-loss-prevention tools) through rule sets keyed to data classification labels, content, or network attributes. In practice, organizations define organization-specific information flow control policies and then implement enforcement mechanisms—such as one-way data diodes, content filters, or export restrictions—to ensure transfers never violate those policies.

MWELegacy lexicon import

Senses

NIST SP 800-171r3attested usage reviewer confirmed

No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.

Classifications

Entity Type

Requirement92%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Sensitivity

unclassified

Information Class

unclassified

Variants

plural
information flow control policies
possessive
information flow control policy's
pluralpossessive
information flow control policies'