STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 2 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← AC-4 (12) — Information Flow Enforcement

CCI-002201

Definition

When transferring information between different security domains, use organization-defined data type identifiers to validate data essential for information flow decisions.

Parent Control

AC-4 (12)Information Flow EnforcementAccess Control

Linked STIG Checks (5)

V-204987CAT IIThe ALG that is part of a CDS, when transferring information between different security domains, must use organization-defined data type identifiers to validate data essential for information flow decisions.Application Layer Gateway Security Requirements GuideV-233857CAT IIThe Infoblox DNS service member must not reveal sensitive information to an attacker. This includes Host Information (HINFO), Responsible Person (RP), Location (LOC) resource, and sensitive text string resource (TXT) record data.Infoblox 8.x DNS Security Technical Implementation GuideV-259403CAT IIThe DNS Name Server software must be configured to refuse queries for its version information.Microsoft Windows Server Domain Name System (DNS) Security Technical Implementation GuideV-259404CAT IIThe HINFO, RP, TXT, and LOC RR types must not be used in the zone SOA.Microsoft Windows Server Domain Name System (DNS) Security Technical Implementation GuideV-279001CAT IIWhen transferring information between different security domains, the router must use organization-defined data type identifiers to validate data essential for information flow decisions.Router Security Requirements Guide