|
control enhancementAC-4(25)

Data Sanitization (AC-4(25))

When transferring information between different security domains, sanitize data to minimize [organization-defined] in accordance with [organization-defined].

access-controlauthorizationleast-privilegeenhancement

Why These Connect

Maps To1

These are equivalent or closely aligned requirements in other frameworks.

Enhances1

These enhancements add specific capabilities or refinements to the base control.

Cross-Framework Mappings(1)

ISO 27001ISO/IEC 27001:20221 mappingFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022

Organization-Defined Parameters(2)

SelectionSelection (one-or-more): delivery of malicious content, command and control of malicious code, malicious code augmentation, and steganography-encoded data / spillage of sensitive information
Assignmentorganization-defined policy