NIST 800-53 r5 · Controls catalogue · Family AC
AC-4Information Flow Enforcement
Enforce approved authorizations for controlling the flow of information within the system and between connected systems based on {{ insert: param, ac-04_odp }}.
Last updated: 22 August 2026 07:11 UTC
Implementations targeting this control (5)
- aws-config-incoming-ssh-disabled Security groups disallow unrestricted SSH ingress AWS::EC2::SecurityGroup partial protect enforce
- azure-mcsb-network-restrict-public-storage Storage accounts deny public-blob access Microsoft.Storage/storageAccounts partial protect enforce
- azure-mcsb-network-flow-logs NSG flow logs are enabled Microsoft.Network/networkSecurityGroups partial protect enforce
- gcp-cis-storage-bucket-public-access-prohibited Cloud Storage buckets disallow allUsers / allAuthenticatedUsers storage.googleapis.com/Bucket partial protect enforce
- gcp-cis-vpc-flow-logs-enabled VPC subnetworks have flow logs enabled compute.googleapis.com/Subnetwork partial protect enforce
ATT&CK techniques this control mitigates (158)
- T1001 Data Obfuscation Command And Control
- T1001.001 Junk Data Command And Control
- T1001.002 Steganography Command And Control
- T1001.003 Protocol or Service Impersonation Command And Control
- T1003 OS Credential Dumping Credential Access
- T1003.001 LSASS Memory Credential Access
- T1003.005 Cached Domain Credentials Credential Access
- T1003.006 DCSync Credential Access
- T1008 Fallback Channels Command And Control
- T1020.001 Traffic Duplication Exfiltration
- T1021.001 Remote Desktop Protocol Lateral Movement
- T1021.002 SMB/Windows Admin Shares Lateral Movement
- T1021.003 Distributed Component Object Model Lateral Movement
- T1021.005 VNC Lateral Movement
- T1021.006 Windows Remote Management Lateral Movement
- T1029 Scheduled Transfer Exfiltration
- T1030 Data Transfer Size Limits Exfiltration
- T1041 Exfiltration Over C2 Channel Exfiltration
- T1046 Network Service Discovery Discovery
- T1048 Exfiltration Over Alternative Protocol Exfiltration
- T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol Exfiltration
- T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol Exfiltration
- T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol Exfiltration
- T1068 Exploitation for Privilege Escalation Privilege Escalation
- T1070.008 Clear Mailbox Data Stealth
- T1071 Application Layer Protocol Command And Control
- T1071.001 Web Protocols Command And Control
- T1071.002 File Transfer Protocols Command And Control
- T1071.003 Mail Protocols Command And Control
- T1071.004 DNS Command And Control
- T1071.005 Publish/Subscribe Protocols Command And Control
- T1072 Software Deployment Tools Execution, Lateral Movement
- T1090 Proxy Command And Control
- T1090.001 Internal Proxy Command And Control
- T1090.002 External Proxy Command And Control
- T1090.003 Multi-hop Proxy Command And Control
- T1095 Non-Application Layer Protocol Command And Control
- T1098 Account Manipulation Persistence, Privilege Escalation
- T1098.001 Additional Cloud Credentials Persistence, Privilege Escalation
- T1098.007 Additional Local or Domain Groups Persistence, Privilege Escalation
- T1102 Web Service Command And Control
- T1102.001 Dead Drop Resolver Command And Control
- T1102.002 Bidirectional Communication Command And Control
- T1102.003 One-Way Communication Command And Control
- T1104 Multi-Stage Channels Command And Control
- T1105 Ingress Tool Transfer Command And Control
- T1114 Email Collection Collection
- T1114.001 Local Email Collection Collection
- T1114.002 Remote Email Collection Collection
- T1114.003 Email Forwarding Rule Collection
Weaknesses this control addresses (8)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-862 | Missing Authorization | 10,200+ | Mandates authorization checks and enforcement for all information flows, addressing missing authorization. |
CWE-284 | Improper Access Control | 6,900+ | Enforcing approved authorizations for information flows directly implements access control over data movements within and between systems. |
CWE-863 | Incorrect Authorization | 3,900+ | Applies only approved authorizations to information flows, mitigating incorrect authorization decisions. |
CWE-285 | Improper Authorization | 1,500+ | Requires and applies authorization decisions specifically to control information flows based on policy. |
CWE-668 | Exposure of Resource to Wrong Sphere | 800+ | Restricts information flows to ensure resources are not exposed to incorrect or unauthorized spheres. |
CWE-669 | Incorrect Resource Transfer Between Spheres | 100+ | Enforces proper authorization rules for any resource or data transfer between different spheres. |
CWE-653 | Improper Isolation or Compartmentalization | 73 | Maintains isolation and compartmentalization by restricting flows between security domains or levels. |
CWE-501 | Trust Boundary Violation | 33 | Prevents information from crossing trust boundaries without explicit approved authorizations. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2026-15409 KEV | 10.0 | 10.0 | 0.7422 | good |
CVE-2024-45507 UPD | 9.9 | 9.8 | 0.9323 | good |
CVE-2023-49785 UPD | 9.4 | 9.1 | 0.8316 | good |
CVE-2026-64849 KEV | 9.3 | 9.3 | 0.0815 | good |
CVE-2025-30220 UPD | 9.2 | 9.9 | 0.5672 | good |
CVE-2025-34291 KEV UPD | 9.2 | 8.8 | 0.8384 | good |
CVE-2024-23898 UPD | 9.0 | 8.8 | 0.6715 | good |
CVE-2024-21893 KEV UPD | 8.9 | 8.2 | 1.0000 | good |
CVE-2026-20230 KEV UPD | 8.8 | 8.6 | 0.8321 | good |
CVE-2024-32964 UPD | 8.5 | 9.0 | 0.5296 | good |
CVE-2025-2828 UPD | 8.5 | 10.0 | 0.1588 | good |
CVE-2026-31431 KEV UPD | 8.5 | 7.8 | 0.9991 | good |
CVE-2024-38472 UPD | 8.3 | 7.5 | 0.6947 | good |
CVE-2025-27817 UPD | 8.3 | 7.5 | 0.6527 | good |
CVE-2024-4325 UPD | 8.0 | 8.6 | 0.3737 | good |
CVE-2024-54819 UPD | 8.0 | 9.1 | 0.1803 | good |
CVE-2025-54381 UPD | 8.0 | 9.9 | 0.1246 | good |
CVE-2026-44578 UPD | 8.0 | 8.6 | 0.3887 | good |
CVE-2025-21385 UPD | 7.9 | 8.8 | 0.2444 | good |
CVE-2024-41570 UPD | 7.8 | 9.8 | 0.0291 | good |
CVE-2024-47008 UPD | 7.8 | 7.5 | 0.4706 | good |
CVE-2024-45518 UPD | 7.8 | 8.8 | 0.2018 | good |
CVE-2025-22952 UPD | 7.8 | 9.8 | 0.0285 | good |
CVE-2026-33626 | 7.8 | 7.5 | 0.4525 | good |
CVE-2023-42282 UPD | 7.6 | 9.8 | 0.0161 | good |