Defines the discretionary access control policies the information system is to enforce over subjects and objects.
No STIG checks reference this CCI.