information flow control policy
163545·updated Aug 30, 2026No definition recorded.
Composition
Source
information flowthe sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.
- information flow control - Glossary | CSRC
- SL5 Standard for AI Security
- AC-4 - NIST 800-53 r5 Control Explorer - GRC Academy
- 3.1.3: Control the flow of CUI in accordance with approved authorizations - CSF Tools
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
A security policy rule set—defined at the organizational or system level—that specifies which subjects, operations, and information attributes govern whether data is permitted to move between designated sources and destinations, independent of who owns or holds the data at any given moment. Information flow control regulates *where* information can travel within a system and between systems, in contrast to who is allowed to access the information. An information flow control policy controls access to the information itself, independent of its container; the attributes of the information stay with it as it flows. In practice the field uses it in two complementary ways: organizations employ information flow control policies and enforcement mechanisms to control the flow of information between designated sources and destinations within systems and between connected systems, with flow control based on the characteristics of the information and/or the information path; and in formal evaluation frameworks such as the Common Criteria (ISO/IEC 15408), FDP_IFC covers the identification of information flow control Security Function Policies (SFPs) and the scope of their control, going beyond
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
No recorded attestations. They are written when an MWE tagging stage is completed, stamped with the pack version and the document’s digest.