AC-03.11 ยท Restrict Access to Specific Information Types

Control Description

Restrict access to data repositories containing {{ insert: param, ac-03.11_odp }}.

Impact Baselines
Security baselines where this control applies
Not in any baseline
Control Properties
SP800-53-enhancement
system
Enhancement
Control Statement
The control requirements

Restrict access to data repositories containing {{ insert: param, ac-03.11_odp }}.

Supplemental Guidance

Restricting access to specific information is intended to provide flexibility regarding access control of specific information types within a system. For example, role-based access could be employed to allow access to only a specific type of personally identifiable information within a database rather than allowing access to the database in its entirety. Other examples include restricting access to cryptographic keys, authentication information, and selected system information.

Related NIST Controls
Other NIST 800-53 controls related to this one