|
control enhancementAC-4(25)
Data Sanitization (AC-4(25))
When transferring information between different security domains, sanitize data to minimize [organization-defined] in accordance with [organization-defined].
access-controlauthorizationleast-privilegeenhancement
Why These Connect
Maps To1
These are equivalent or closely aligned requirements in other frameworks.
Enhances1
These enhancements add specific capabilities or refinements to the base control.
Cross-Framework Mappings(1)
ISO 27001ISO/IEC 27001:20221 mappingFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
Organization-Defined Parameters(2)
SelectionSelection (one-or-more): delivery of malicious content, command and control of malicious code, malicious code augmentation, and steganography-encoded data / spillage of sensitive information
Assignmentorganization-defined policy