<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://cmmcwiki.org/index.php?action=history&amp;feed=atom&amp;title=Practice_AC.L3-3.1.3e_Details</id>
	<title>Practice AC.L3-3.1.3e Details - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://cmmcwiki.org/index.php?action=history&amp;feed=atom&amp;title=Practice_AC.L3-3.1.3e_Details"/>
	<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=Practice_AC.L3-3.1.3e_Details&amp;action=history"/>
	<updated>2026-05-26T11:36:51Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.8</generator>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=Practice_AC.L3-3.1.3e_Details&amp;diff=1191&amp;oldid=prev</id>
		<title>David at 02:13, 25 March 2025</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=Practice_AC.L3-3.1.3e_Details&amp;diff=1191&amp;oldid=prev"/>
		<updated>2025-03-25T02:13:14Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;a href=&quot;https://cmmcwiki.org/index.php?title=Practice_AC.L3-3.1.3e_Details&amp;amp;diff=1191&amp;amp;oldid=1187&quot;&gt;Show changes&lt;/a&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=Practice_AC.L3-3.1.3e_Details&amp;diff=1187&amp;oldid=prev</id>
		<title>David: Created page with &quot;&#039;&#039;&#039;Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Level 3 Assessment Guide] from the Department of Defense Chief Information Officer (DoD CIO).&#039;&#039;&#039;  For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you.  == AC.L3-3.1.3E – SECURED INFORMATION TRANSFER == === SECURITY REQUIREMENT === Employ secure information transfer solutions to control information flows between s...&quot;</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=Practice_AC.L3-3.1.3e_Details&amp;diff=1187&amp;oldid=prev"/>
		<updated>2025-03-24T22:35:32Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;&amp;#039;&amp;#039;&amp;#039;Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Level 3 Assessment Guide] from the Department of Defense Chief Information Officer (DoD CIO).&amp;#039;&amp;#039;&amp;#039;  For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you.  == AC.L3-3.1.3E – SECURED INFORMATION TRANSFER == === SECURITY REQUIREMENT === Employ secure information transfer solutions to control information flows between s...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Level 3 Assessment Guide] from the Department of Defense Chief Information Officer (DoD CIO).&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you.&lt;br /&gt;
&lt;br /&gt;
== AC.L3-3.1.3E – SECURED INFORMATION TRANSFER ==&lt;br /&gt;
=== SECURITY REQUIREMENT ===&lt;br /&gt;
Employ secure information transfer solutions to control information flows between security domains on connected systems.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;ASSESSMENT OBJECTIVES [NIST SP 800-172A] &amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
Determine if: &amp;lt;br /&amp;gt;&lt;br /&gt;
[ODP1] Secure information transfer solutions are defined; &amp;lt;br /&amp;gt;&lt;br /&gt;
[a] Information flows between security domains on connected systems are identified; and &amp;lt;br /&amp;gt;&lt;br /&gt;
[b] Secure information transfer solutions are employed to control information flows &lt;br /&gt;
&lt;br /&gt;
between security domains on connected systems.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;POTENTIAL ASSESSMENT METHODS AND OBJECTS [NIST SP 800-172A] &amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Examine &amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;[SELECT FROM: Access control policy; information flow control policies; procedures &lt;br /&gt;
&lt;br /&gt;
addressing information flow enforcement; system design documentation; security plan;&lt;br /&gt;
&lt;br /&gt;
system configuration settings and associated documentation; system audit records; system &lt;br /&gt;
&lt;br /&gt;
baseline configuration; list of information flow authorizations; other relevant documents or &lt;br /&gt;
&lt;br /&gt;
records].&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Interview &amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;[SELECT FROM: System and network administrators; organizational personnel responsible &lt;br /&gt;
&lt;br /&gt;
for information security; system developers].&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Test &amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;[SELECT FROM: Mechanisms implementing information flow enforcement policy;&lt;br /&gt;
&lt;br /&gt;
mechanisms implementing secure information transfer solutions].&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;DISCUSSION [NIST SP 800-172] &amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
Organizations employ information flow control policies and enforcement mechanisms to &lt;br /&gt;
&lt;br /&gt;
control the flow of information between designated sources and destinations within systems &lt;br /&gt;
&lt;br /&gt;
and between connected systems. Flow control is based on the characteristics of the &lt;br /&gt;
&lt;br /&gt;
information and/or the information path. Enforcement occurs, for example, in boundary &lt;br /&gt;
&lt;br /&gt;
protection devices that employ rule sets or establish configuration settings that restrict &lt;br /&gt;
&lt;br /&gt;
system services, provide a packet-filtering capability based on header information, or &lt;br /&gt;
&lt;br /&gt;
provide a message-filtering capability based on message content. Organizations also &lt;br /&gt;
&lt;br /&gt;
consider the trustworthiness of filtering and inspection mechanisms (i.e., hardware, &lt;br /&gt;
&lt;br /&gt;
firmware, and software components) that are critical to information flow enforcement. &amp;lt;br /&amp;gt;&lt;br /&gt;
Transferring information between systems in different security domains with different &lt;br /&gt;
&lt;br /&gt;
security policies introduces the risk that the transfers violate one or more domain security &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
AC.L3-3.1.3e – Secured Information Transfer &lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;CMMC Assessment Guide – Level 3 &amp;#039;&amp;#039;&amp;#039;|&amp;#039;&amp;#039;&amp;#039; Version 2.13 &amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
18 &lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
policies. In such situations, information owners or information stewards provide guidance &lt;br /&gt;
&lt;br /&gt;
at designated policy enforcement points between connected systems. Organizations &lt;br /&gt;
&lt;br /&gt;
mandate specific architectural solutions when required to enforce logical or physical &lt;br /&gt;
&lt;br /&gt;
separation between systems in different security domains. Enforcement includes prohibiting &lt;br /&gt;
&lt;br /&gt;
information transfers between connected systems, employing hardware mechanisms to &lt;br /&gt;
&lt;br /&gt;
enforce one-way information flows, verifying write permissions before accepting &lt;br /&gt;
&lt;br /&gt;
information from another security domain or connected system, and implementing &lt;br /&gt;
&lt;br /&gt;
trustworthy regrading mechanisms to reassign security attributes and labels. &amp;lt;br /&amp;gt;&lt;br /&gt;
Secure information transfer solutions often include one or more of the following properties:&lt;br /&gt;
&lt;br /&gt;
use of cross-domain solutions when traversing security domains, mutual authentication of &lt;br /&gt;
&lt;br /&gt;
the sender and recipient (using hardware-based cryptography), encryption of data in transit &lt;br /&gt;
&lt;br /&gt;
and at rest, isolation from other domains, and logging of information transfers (e.g., title of &lt;br /&gt;
&lt;br /&gt;
file, file size, cryptographic hash of file, sender, recipient, transfer time and Internet Protocol &lt;br /&gt;
&lt;br /&gt;
[IP] address, receipt time, and IP address).&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;FURTHER DISCUSSION &amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
The organization implementing this requirement must decide on the secure information &lt;br /&gt;
&lt;br /&gt;
transfer solutions they will use. The solutions must be configured to have strong protection &lt;br /&gt;
&lt;br /&gt;
mechanisms for information flow between security domains. Secure information transfer &lt;br /&gt;
&lt;br /&gt;
solutions control information flow between a Level 3 enclave and other CMMC or non-CMMC &lt;br /&gt;
&lt;br /&gt;
enclaves. If CUI requiring Level 3 protection resides in one area of the environment or within &lt;br /&gt;
&lt;br /&gt;
a given enclave outside of the normal working environment, protection to prevent &lt;br /&gt;
&lt;br /&gt;
unauthorized personnel from accessing, disseminating, and sharing the protected &lt;br /&gt;
&lt;br /&gt;
information is required. Physical and virtual methods can be employed to implement secure &lt;br /&gt;
&lt;br /&gt;
information transfer solutions.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Example &amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;You are the administrator for an enterprise that stores and processes CUI requiring Level 3 &lt;br /&gt;
&lt;br /&gt;
protection. The files containing CUI information are tagged by the company as CUI. To ensure &lt;br /&gt;
&lt;br /&gt;
secure information transfer, you use an intermediary device to check the transfer of any CUI &lt;br /&gt;
&lt;br /&gt;
files. The device sits at the boundary of the CUI enclave, is aware of all other CUI domains in &lt;br /&gt;
&lt;br /&gt;
the enterprise, and has the ability to examine the metadata in the encrypted payload. The &lt;br /&gt;
&lt;br /&gt;
tool checks all outbound communications paths. It first checks the metadata for all data being &lt;br /&gt;
&lt;br /&gt;
transferred. If that data is identified as CUI, the device checks the destination to see if the &lt;br /&gt;
&lt;br /&gt;
transfer is to another, sufficiently certified CUI domain. If the destination is not a sufficient &lt;br /&gt;
&lt;br /&gt;
CUI domain, the tool blocks the communication path and does not allow the transfer to take &lt;br /&gt;
&lt;br /&gt;
place. If the destination is a sufficient CUI domain, the transfer is allowed. The intermediary &lt;br /&gt;
&lt;br /&gt;
device logs all blocks.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Potential Assessment Considerations &amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;•&lt;br /&gt;
&lt;br /&gt;
 Has the organization defined the secure information transfer solutions it is using [b]? &lt;br /&gt;
&lt;br /&gt;
•&lt;br /&gt;
&lt;br /&gt;
 Has the organization defined domains, boundaries, and flows between those domains &lt;br /&gt;
&lt;br /&gt;
that need to be controlled [a]? &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
AC.L3-3.1.3e – Secured Information Transfer &lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;CMMC Assessment Guide – Level 3 &amp;#039;&amp;#039;&amp;#039;|&amp;#039;&amp;#039;&amp;#039; Version 2.13 &amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
19 &lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
•&lt;br /&gt;
&lt;br /&gt;
 Has the organization defined attributes to be associated with the CUI, and both source &lt;br /&gt;
&lt;br /&gt;
and destination objects [b]? &lt;br /&gt;
&lt;br /&gt;
•&lt;br /&gt;
&lt;br /&gt;
 Has the organization defined metadata or some other tagging mechanism to be used as a &lt;br /&gt;
&lt;br /&gt;
means of enforcing CUI flow control [b]? &lt;br /&gt;
&lt;br /&gt;
•&lt;br /&gt;
&lt;br /&gt;
 Has the organization defined filters to be used as a basis for enforcing flow control &lt;br /&gt;
&lt;br /&gt;
decisions [b]? &lt;br /&gt;
&lt;br /&gt;
•&lt;br /&gt;
&lt;br /&gt;
 Has the organization identified CUI flows for which flow control decisions are to be &lt;br /&gt;
&lt;br /&gt;
applied and enforced [a,b]? &lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;KEY REFERENCES &amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
•&lt;br /&gt;
&lt;br /&gt;
 NIST SP 800-172 3.1.3e&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
</feed>