home/glossary/one-way information flow

one-way information flow

nounverified·updated Aug 30, 2026

An architectural security property of an information path between two systems or domains in which data is permitted to travel in only one direction — from source to destination — with no return channel possible. It distinguishes itself from general access control by regulating *where* data can travel rather than *who* may access it, making bidirectional communication structurally or physically impossible rather than merely policy-prohibited. Standards bodies such as NIST (SP 800-53 AC-4 and SP 800-171 3.1.3) cite it as an enforcement mechanism alongside write-permission verification and regrading, specifically "employing hardware mechanisms to enforce one-way information flows" — typically realized as a data diode or unidirectional security gateway — applied wherever networks of differing confidentiality or integrity must be separated, such as preventing back-channel exfiltration into classified networks or blocking malware ingress into high-integrity industrial control systems.

MWELegacy lexicon import

Senses

NIST SP 800-171r3attested usage reviewer confirmed

No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.

Classifications

Entity Type

Control92%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Sensitivity

Regulated85%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Information Class

Cui75%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Variants

plural
one-way information flows
possessive
one-way information flow's
pluralpossessive
one-way information flows'