{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Network & Communications Security","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-NET-14","description":"Associate security and privacy attributes (labels) with information exchanged between systems and preserve them in transmission so receiving systems can enforce handling policy. Enforce mandatory information-exchange policy at cross-domain interconnection points so only authorized data types and flow directions are permitted between security domains.","details":{"control_category":"technical","control_type":"preventive","domain":"Network & Communications Security","guidance":[],"members":[{"control_id":"SC-46","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SC-16","coverage":"full","framework":"nist-800-53","relationship":"superset_of"}],"statement":"Associate security and privacy attributes (labels) with information exchanged between systems and preserve them in transmission so receiving systems can enforce handling policy. Enforce mandatory information-exchange policy at cross-domain interconnection points so only authorized data types and flow directions are permitted between security domains.","title":"Enforce policy on cross-domain information exchange","unified_id":"UC-NET-14"},"id":"uc:UC-NET-14","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-NET-14","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"UC-NET-14 — Enforce policy on cross-domain information exchange","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:11afed6ff3a04605fedc03979f7728595f8a27c1260f33594854cc2fc8ee6a6f","properties":{"rationale":"Enforcing authorized flow directions/types at cross-domain interconnections constrains the permitted flows abused for egress.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-net-14-bacae152.json","sourceId":"uc:UC-NET-14","targetDetailPath":"/data/v1/records/risk-net-session-hijacking-434ddd0c.json","targetId":"risk:net-session-hijacking","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2acaf0d9d3fdc7fe2c36a4447e7b431d9b006026d525f2dd18bc9b3e0e307d12","properties":{"rationale":"Binding and enforcing security/privacy attribute labels and permitted data types filters unauthorized/untrusted data crossing domains.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-net-14-bacae152.json","sourceId":"uc:UC-NET-14","targetDetailPath":"/data/v1/records/risk-net-untrustworthy-input-data-6465a381.json","targetId":"risk:net-untrustworthy-input-data","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5d40a663ef7073099a40573314fc80e3f6710b0215ccca0a6f6b5e33185f5ab4","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-net-14-bacae152.json","targetId":"uc:UC-NET-14","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:65cb890f9b161bc7a4f7d7e0fed0a58f0cfa4e826b7ba2c086481d3f2efd559e","properties":{"control_id":"SC-16","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-14-bacae152.json","sourceId":"uc:UC-NET-14","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-16-8c0dae07.json","targetId":"ctrl:nist-800-53:SC-16","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7402c1b1f98dac36439176007fcb4c5396c8b566310f93698acf433abc7654ee","properties":{"control_id":"SC-46","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-14-bacae152.json","sourceId":"uc:UC-NET-14","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-46-f1a5e547.json","targetId":"ctrl:nist-800-53:SC-46","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:da98b9dcbb9458716349a3f2c91af12c908e1072d9152a7ec00a2b158db4795e","properties":{},"sourceDetailPath":"/data/v1/records/wf-c48-1fcd5f42.json","sourceId":"wf:C48","targetDetailPath":"/data/v1/records/uc-uc-net-14-bacae152.json","targetId":"uc:UC-NET-14","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ef6b2eb12e590b37a925e130949f3959cb02d9bfc83debc66312eb30fd69fc52","properties":{"rationale":"Enforcing mandatory cross-domain policy that permits only authorized data types and flow directions blocks unauthorized data egress between domains.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-net-14-bacae152.json","sourceId":"uc:UC-NET-14","targetDetailPath":"/data/v1/records/risk-data-exfiltration-espionage-74803ebc.json","targetId":"risk:data-exfiltration-espionage","type":"mitigates"}],"schemaVersion":1}
