one-way information flow
163543·updated Aug 30, 2026An architectural security property of an information path between two systems or domains in which data is permitted to travel in only one direction — from source to destination — with no return channel possible. It distinguishes itself from general access control by regulating *where* data can travel rather than *who* may access it, making bidirectional communication structurally or physically impossible rather than merely policy-prohibited. Standards bodies such as NIST (SP 800-53 AC-4 and SP 800-171 3.1.3) cite it as an enforcement mechanism alongside write-permission verification and regrading, specifically "employing hardware mechanisms to enforce one-way information flows" — typically realized as a data diode or unidirectional security gateway — applied wherever networks of differing confidentiality or integrity must be separated, such as preventing back-channel exfiltration into classified networks or blocking malware ingress into high-integrity industrial control systems.
Source
to enforce one-waythe sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.
- AC-4 - NIST 800-53 r5 Control Explorer - GRC Academy
- 3.1.3 - NIST 800-171 r2 Control Explorer - GRC Academy
- Hardware-enforced one-way information flow control device
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
A security architecture property — and its corresponding enforcement mechanism — that permits data to travel in only one direction between two domains, networks, or trust boundaries, making any reverse channel physically or logically impossible. It is distinguished from ordinary access control by its absolute, non-negotiable directionality: when information must be transferred between isolated networks of differing confidentiality or integrity, established information security models such as Bell-LaPadula and Biba favor implementation of one-way information flow controls, because bidirectionality — even the mere capability of it — constitutes a security or integrity risk. NIST SP 800-53 AC-4(7) requires organizations to enforce one-way information flows through hardware-based flow control mechanisms, and notes that such mechanisms may also be referred to as a unidirectional network, unidirectional security gateway, or data diode. In practice the field uses it to describe the goal (the directional property to be enforced), the policy (the rule stating that data must not cross a boundary in the prohibited direction), and the class of control (software filters, or more robustly, hardw
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- one-way information flows
- possessive
- one-way information flow's
- pluralpossessive
- one-way information flows'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- An architectural security property of an information path between two systems or domains in which data is permitted to travel in only one direction — from source to destination — with no return channel possible. It distinguishes itself from general access control by regulating *where* data can travel rather than *who* may access it, making bidirectional communication structurally or physically impossible rather than merely policy-prohibited. Standards bodies such as NIST (SP 800-53 AC-4 and SP 800-171 3.1.3) cite it as an enforcement mechanism alongside write-permission verification and regrading, specifically "employing hardware mechanisms to enforce one-way information flows" — typically realized as a data diode or unidirectional security gateway — applied wherever networks of differing confidentiality or integrity must be separated, such as preventing back-channel exfiltration into classified networks or blocking malware ingress into high-integrity industrial control systems.DR-088 backfill from the noun definition column