Uploaded image for project: 'OpenShift CFE'
  1. OpenShift CFE
  2. CFE-290

AC-4(8) - Security policy filters

XMLWordPrintable

      The information system enforces information flow control using [Assignment: organization-defined security policy filters] as a basis for flow control decisions for [Assignment: organization-defined information flows].

      Supplemental Guidance:  Organization-defined security policy filters can address data structures and content. For example, security policy filters for data structures can check for maximum file lengths, maximum field sizes, and data/file types (for structured and unstructured data). Security policy filters for data content can check for specific words (e.g., dirty/clean word filters), enumerated values or data value ranges, and hidden content. Structured data permits the interpretation of data content by applications. Unstructured data typically refers to digital information without a particular data structure or with a data structure that does not facilitate the development of rule sets to address the particular sensitivity of the information conveyed by the data or the associated flow enforcement decisions. Unstructured data consists of: bitmap objects that are inherently non language-based (i.e., image, video, or audio files); and (ii) textual objects that are based on written or printed languages (e.g., commercial off-the- shelf word processing documents, spreadsheets, or emails). Organizations can implement more than one security policy filter to meet information flow control objectives (e.g., employing clean word lists in conjunction with dirty word lists may help to reduce false positives).

       

      References:

      https://issues.redhat.com/browse/CMP-103

       

      Work to do:

      • Explore security policies applicable to openshift (pod, network, scc, rbac)
      • Feedback from compliance and secuirty team
      • Identify and implement policy rules
      • Update control response
      • Remediations applicable that can be set in config

              bhb@redhat.com Bharath B
              tgeer@redhat.com Trilok Geer
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: