information flow control policy
163545·updated Aug 30, 2026A security or privacy policy construct that specifies the authorized paths and directions along which data may move—within a system, between systems, or across security/privacy domains—based on the characteristics of the information itself or its path rather than on who holds access rights to it. It is distinct from access control policy in that it governs *where* information may travel rather than *who* may read it, and it is typically enforced at boundary devices (firewalls, guards, proxies, data-loss-prevention tools) through rule sets keyed to data classification labels, content, or network attributes. In practice, organizations define organization-specific information flow control policies and then implement enforcement mechanisms—such as one-way data diodes, content filters, or export restrictions—to ensure transfers never violate those policies.
Source
information flowthe sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.
- information flow control - Glossary | CSRC
- SL5 Standard for AI Security
- AC-4 - NIST 800-53 r5 Control Explorer - GRC Academy
- 3.1.3: Control the flow of CUI in accordance with approved authorizations - CSF Tools
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
A security policy rule set—defined at the organizational or system level—that specifies which subjects, operations, and information attributes govern whether data is permitted to move between designated sources and destinations, independent of who owns or holds the data at any given moment. Information flow control regulates *where* information can travel within a system and between systems, in contrast to who is allowed to access the information. An information flow control policy controls access to the information itself, independent of its container; the attributes of the information stay with it as it flows. In practice the field uses it in two complementary ways: organizations employ information flow control policies and enforcement mechanisms to control the flow of information between designated sources and destinations within systems and between connected systems, with flow control based on the characteristics of the information and/or the information path; and in formal evaluation frameworks such as the Common Criteria (ISO/IEC 15408), FDP_IFC covers the identification of information flow control Security Function Policies (SFPs) and the scope of their control, going beyond
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- information flow control policies
- possessive
- information flow control policy's
- pluralpossessive
- information flow control policies'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A security or privacy policy construct that specifies the authorized paths and directions along which data may move—within a system, between systems, or across security/privacy domains—based on the characteristics of the information itself or its path rather than on who holds access rights to it. It is distinct from access control policy in that it governs *where* information may travel rather than *who* may read it, and it is typically enforced at boundary devices (firewalls, guards, proxies, data-loss-prevention tools) through rule sets keyed to data classification labels, content, or network attributes. In practice, organizations define organization-specific information flow control policies and then implement enforcement mechanisms—such as one-way data diodes, content filters, or export restrictions—to ensure transfers never violate those policies.DR-088 backfill from the noun definition column