designated source
163547·updated Aug 30, 2026An endpoint — a network, individual, or device — that has been explicitly authorized and named in an information flow control policy as a permitted origin of information movement within or between systems, distinct from *who* may access the information. Flow control policies operate on the characteristics of the information or the information path, and enforcement is carried out in boundary protection devices such as firewalls, routers, and gateways that apply rule sets or packet- and message-filtering capabilities. In practice, organizations use information flow control policies and enforcement mechanisms to govern the movement of sensitive data (e.g., CUI) between designated sources and destinations, regulating *where* information may travel rather than merely *who* may see it. The expression is strictly paired — a source has meaning only relative to a corresponding destination — and the "designated" qualifier signals that the endpoint has been deliberately enumerated in policy, not simply inferred at runtime.
Source
between designated sources and destinations (e.g., networks, individuals, and devices) within systems and betweenthe sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: compositional.
- AC-4: Information Flow Enforcement - CSF Tools
- NIST 800-53 AC-4 - Mappings Explorer
- NIST SP 800-171r3
- SECURITY CONTROL CATALOG - CSRC
- NIST SP 800-53 Rev. 4 – INFORMATION FLOW ENFORCEMENT | Compliance 360 Software
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
A policy-defined endpoint — such as a network, individual, device, or system — that has been explicitly authorized as a permissible origin or starting point for information flows under an organization's information flow control policy. Information flow control governs where information can travel within a system and between systems, in contrast to who is allowed to access the information. Organizations use information flow control policies and enforcement mechanisms to control the flow of information between designated sources and destinations — for example, networks, individuals, and devices — within systems and between interconnected systems. Enforcement is implemented in boundary protection devices through rule sets, packet-filtering, or message-filtering, with organizations also considering the trustworthiness of the filtering and inspection mechanisms that are critical to that enforcement.
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- designated sources
- possessive
- designated source's
- pluralpossessive
- designated sources'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- An endpoint — a network, individual, or device — that has been explicitly authorized and named in an information flow control policy as a permitted origin of information movement within or between systems, distinct from *who* may access the information. Flow control policies operate on the characteristics of the information or the information path, and enforcement is carried out in boundary protection devices such as firewalls, routers, and gateways that apply rule sets or packet- and message-filtering capabilities. In practice, organizations use information flow control policies and enforcement mechanisms to govern the movement of sensitive data (e.g., CUI) between designated sources and destinations, regulating *where* information may travel rather than merely *who* may see it. The expression is strictly paired — a source has meaning only relative to a corresponding destination — and the "designated" qualifier signals that the endpoint has been deliberately enumerated in policy, not simply inferred at runtime.DR-088 backfill from the noun definition column