subsequent access
163532·updated Aug 30, 2026A characteristic of the **information flow control** decision model in which the governing question is where information may travel (path, transit, routing) rather than who may read or use it at any point after it arrives. Flow control policy is evaluated at the moment of transit and is orthogonal to — and deliberately decoupled from — whatever access-control decisions may follow once the information reaches its destination; the two policy dimensions answer different questions and are applied at different enforcement points. Standards bodies including NIST use the phrase in supplemental guidance for AC-4 / SP 800-171 §3.1.3 to explain that an information flow control policy is complete and correctly applied even if it takes no account of what subjects will do with the data downstream.
Source
can transit within a system and between systems (in contrast to who is allowed to access the information) and without regard to subsequent accesses to that information.the sentence this term was read in
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- subsequent accesses
- possessive
- subsequent access's
- pluralpossessive
- subsequent accesses'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · legacy_primary
- A characteristic of the **information flow control** decision model in which the governing question is where information may travel (path, transit, routing) rather than who may read or use it at any point after it arrives. Flow control policy is evaluated at the moment of transit and is orthogonal to — and deliberately decoupled from — whatever access-control decisions may follow once the information reaches its destination; the two policy dimensions answer different questions and are applied at different enforcement points. Standards bodies including NIST use the phrase in supplemental guidance for AC-4 / SP 800-171 §3.1.3 to explain that an information flow control policy is complete and correctly applied even if it takes no account of what subjects will do with the data downstream.DR-088 backfill from the noun definition column