agreement that specifies how the information flow is enforced
163599·updated Sep 1, 2026A formal, documented commitment between two or more organizations — typically an interconnection security agreement (ISA), memorandum of understanding/agreement (MOU/MOA), or data-sharing contract — whose specific purpose is to articulate the technical and policy rules that govern *how* data is permitted to move across an organizational or security-domain boundary and how those rules are actively implemented and verified. Information flow control regulates where information can travel within a system and between systems — in contrast to who is allowed to access the information — and without regard to subsequent accesses to that information. Such an agreement is invoked precisely when two parties operate under different security or privacy policies, because transferring information between systems in different security or privacy domains with different security or privacy policies introduces the risk that such transfers violate one or more domain security or privacy policies. In practice, enforcement includes prohibiting information transfers between connected systems, verifying write permissions before accepting information from another security or privacy domain, employing hardwar
Source
between organizations may require an agreement that specifies how thethe sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: compositional.
- AC-4: Information Flow Enforcement - CSF Tools
- – AC-4 INFORMATION FLOW ENFORCEMENT | NIST SP 800-53
- AC-4 - NIST 800-53 r5 Control Explorer - GRC Academy
- NIST 800-53 AC-4 - Mappings Explorer
- Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171) - Canadian Centre for Cyber Security
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
A contractual or formal instrument — such as an interconnection security agreement (ISA) or memorandum of understanding — that documents the specific rules, technical controls, and policy constraints governing how data is permitted to move across an organizational or security-domain boundary, and that binds both parties to those constraints. Information flow control in this context regulates *where* information can travel within and between systems, distinct from who is allowed to access it. Such an agreement becomes necessary when transferring information between organizations, particularly when connected systems span different security or privacy domains with differing policies, creating the risk that transfers could violate one or more of those policies. Enforcement is realized through boundary protection mechanisms — encrypted tunnels, routers, gateways, firewalls — using rule sets, packet-filtering on headers, or message-filtering on content. In NIST SP 800-53 Rev. 5 (AC-4), the agreement cross-references CA-3 (Interconnection Agreements), making clear that the "agreement" in question is an already-established instrument type, not a new concept; the phrase simply describes wha
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- agreement that specifies how the information flow is enforceds
- possessive
- agreement that specifies how the information flow is enforced's
- pluralpossessive
- agreement that specifies how the information flow is enforceds'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A formal, documented commitment between two or more organizations — typically an interconnection security agreement (ISA), memorandum of understanding/agreement (MOU/MOA), or data-sharing contract — whose specific purpose is to articulate the technical and policy rules that govern *how* data is permitted to move across an organizational or security-domain boundary and how those rules are actively implemented and verified. Information flow control regulates where information can travel within a system and between systems — in contrast to who is allowed to access the information — and without regard to subsequent accesses to that information. Such an agreement is invoked precisely when two parties operate under different security or privacy policies, because transferring information between systems in different security or privacy domains with different security or privacy policies introduces the risk that such transfers violate one or more domain security or privacy policies. In practice, enforcement includes prohibiting information transfers between connected systems, verifying write permissions before accepting information from another security or privacy domain, employing hardwarDR-088 backfill from the noun definition column