AC-15 Automated Marking

Access Control

Low Moderate High

Description

The information system marks output using standard naming conventions to identify any special dissemination, handling, or distribution instructions.

Supplemental Guidance

Automated marking refers to markings employed on external media (e.g., hardcopy documents output from the information system). The markings used in external marking are distinguished from the labels used on internal data structures described in AC-16.

Enhancements

(0) None.

Compliance Mappings

COBIT 2019

DSS05

ISO 42001:2023

A.7.4

NIS2 Directive

Art. 21(2)(i)

MAS TRM

9

BSI IT-Grundschutz

ORP.4

ANSSI

Hygiene.8

FINMA Circular 2023/1

IV.D(78)IV.D(79)

OSFI B-13

B-13.3.2

EU GDPR

Art.5(1)(f)

EU DORA

Art.8(1)

HKMA TM-E-1

TME1.7.2

CBB TM

TM-9

ISO 17799 (legacy)

7.2.2

COBIT 4.1 (legacy)

PO2.3DS11.6AC2