subsequent access
A characteristic of the **information flow control** decision model in which the governing question is where information may travel (path, transit, routing) rather than who may read or use it at any point after it arrives. Flow control policy is evaluated at the moment of transit and is orthogonal to — and deliberately decoupled from — whatever access-control decisions may follow once the information reaches its destination; the two policy dimensions answer different questions and are applied at different enforcement points. Standards bodies including NIST use the phrase in supplemental guidance for AC-4 / SP 800-171 §3.1.3 to explain that an information flow control policy is complete and correctly applied even if it takes no account of what subjects will do with the data downstream.
Senses
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- subsequent accesses
- possessive
- subsequent access's
- pluralpossessive
- subsequent accesses'