STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 4 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← All Controls

AC-16

Access ControlRev 3

Security and Privacy Attributes

CCI Identifiers (38)

CCI-001396The organization defines security attributes for which the information system supports and maintains the bindings for information in storage.CCI-001397The organization defines security attributes for which the information system supports and maintains the bindings for information in process.CCI-001398The organization defines security attributes for which the information system supports and maintains the bindings for information in transmission.CCI-001399The information system supports and maintains the binding of organization-defined security attributes to information in storage.CCI-001400The information system supports and maintains the binding of organization-defined security attributes to information in process.CCI-001401The information system supports and maintains the binding of organization-defined security attributes to information in transmission.CCI-002256Defines security attributes having organization-defined types of security attribute values which are associated with information in storage.CCI-002257Defines security attributes having organization-defined types of security attribute values which are associated with information in process.CCI-002258Defines security attributes, having organization-defined types of security attribute values, which are associated with information in transmission.CCI-002259Defines security attribute values associated with organization-defined types of security attributes for information in storage.CCI-002260Defines security attribute values associated with organization-defined types of security attributes for information in process.CCI-002261Defines security attribute values associated with organization-defined types of security attributes for information in transmission.CCI-002262Provide the means to associate organization-defined types of security attributes having organization-defined security attribute values with information in storage.CCI-002263Provide the means to associate organization-defined types of security attributes having organization-defined security attribute values with information in process.CCI-002264Provide the means to associate organization-defined types of security attributes having organization-defined security attribute values with information in transmission.CCI-002265Ensure that the attribute associations are made and retained with the information.CCI-002266Ensure that the security attribute associations are retained with the information.CCI-002267Defines the security attributes that are permitted for organization-defined systems.CCI-002268Defines the systems for which permitted organization-defined attributes are to be established.CCI-002269Establish the following permitted organization-defined security attributes in AC-16a for organization-defined systems.CCI-002270Defines the attribute values or ranges permitted for each of the established security attributes.CCI-002271Determine organization-defined attribute values or ranges for each of the established attributes.CCI-003696Defines privacy attributes having organization-defined types of privacy attribute values which are associated with information in storage.CCI-003697Defines privacy attributes having organization-defined types of privacy attribute values which are associated with information in process.CCI-003698Defines privacy attributes, having organization-defined types of privacy attribute values, which are associated with information in transmission.CCI-003699Defines privacy attribute values associated with organization-defined types of privacy attributes for information in storage.CCI-003700Defines privacy attribute values associated with organization-defined types of privacy attributes for information in process.CCI-003701Defines privacy attribute values associated with organization-defined types of privacy attributes for information in transmission.CCI-003702Ensure that the privacy attribute associations are made with the information.CCI-003703Ensure that the privacy attribute associations are restrained with the information.CCI-003704Establish the following permitted organization-defined privacy attributes defined in AC-16a for organization-defined systems.CCI-003705Defines the privacy attributes that are permitted for organization-defined systems.CCI-003706Defines the attribute values or ranges permitted for each of the established privacy attributes.CCI-003707Audit changes to the attributes.CCI-003708Review organization-defined security attributes for applicability on an organization-defined frequency.CCI-003709Review organization-defined privacy attributes for applicability on an organization-defined frequency.CCI-003710Defines the security and privacy attributes to be reviewed for applicability.CCI-003711Defines the frequency of which the security and privacy attributes will be reviewed.

Linked STIG Checks (68)

Across 33 STIGs. Click to expand.