Contents

Introduction

This document specifies the NATO ACP240 Attribute Mapping. It comprises one of the additional specifications of the CABE Architecture, as defined in the CABE Architecture Specification.

The CABE Architecture defines the concept of an Attribute Set, which is a set of key value pairs characterising a CABE Message or CABE Envelope. This document defines an attribute mapping aligned with the NATO ACP240 architecture and and the STANAG 4774 labelling scheme.

Definitions

The key words “MUST”, “MUST NOT”, “REQUIRED”, “SHALL”, “SHALL NOT”, “SHOULD”, “SHOULD NOT”, “RECOMMENDED”, “NOT RECOMMENDED”, “MAY” and “OPTIONAL” in this document are to be interpreted as specified in BCP 14 when, and only when, they appear in all capitals, as shown here.

All definitions given in the CABE Architecture Specification are reused for the purposes of this document.

Scope

This document defines a mapping for a subset of the full NATO ACP240 / STANAG 4774 classification taxonomy.

Defined Attributes

p (policyIdentifier)

The p attribute corresponds to the STANAG 4774 policyIdentifier field. It MUST be present and MUST conform to the following ABNF:

  POLICY_IDENTIFIER  = COUNTRY / "NATO" / "PUBLIC"
  COUNTRY            = 3UPPER_ALPHA
  UPPER_ALPHA        = %x41-5A

s (sensitivity)

The s attribute corresponds to the STANAG 4774 classification field. It MUST be present. The values for this field MUST be uppercase.

When p is set to "NATO" it MUST be set to one of the following values:

  • "UNCLASSIFIED"
  • "RESTRICTED"
  • "CONFIDENTIAL"
  • "SECRET"
  • "TOP SECRET"

When p is set to "PUBLIC", it MUST be set to "UNMARKED".

When p is set to a country code, the valid values are dependent on the specific policy of that country.

r (releasability)

The r attribute corresponds to the STANAG 4774 releasability field. It MAY be present. If present, it MUST be a string containing a comma separated list of uppercase values sorted in ascending lexicographic order. A given value MUST NOT appear twice. The list MAY be empty, in which case it is represented as the empty string.

These requirements are intended to create a canonical representation for a logical set of country codes.

Values MUST conform to the following ABNF.

  # List must be sorted in ascending lexicographic order
  # List must not contain duplicates
  R_VALUE       = [R_ITEM *(',' R_ITEM)]
  R_ITEM        = SPECIAL_GROUP / COUNTRY
  SPECIAL_GROUP = 1*(UPPER_ALPHA / SP)
  # COUNTRY, UPPER_ALPHA are defined as under `p`

c (context)

The c attribute corresponds to the STANAG 4774 Category element with a TagName of Context and a Type of PERMISSIVE.

The exact semantics depend on the chosen value of p. However, regardless of the specific value of p, if present, it MUST be a string containing a (possibly empty) comma separated list of uppercase values sorted in ascending lexicographic order, which conforms to the following ABNF:

  CONTEXT     = [C_VALUE *(',' C_VALUE)
  C_VALUE     = 1*UPPER_ALPHA *(SP 1*UPPER_ALPHA)

Regardless of the value of p, if c is present, a given value in the comma-separated list MUST NOT appear more than once.

Implementations MUST NOT produce invalid encodings of c and MUST NOT accept invalid encodings of c. Examples of invalid encodings include:

  • an encoding not matching the above ABNF (e.g. lowercase characters, trailing comma)
  • non-canonical sort order
  • duplicate values

Implementations which support a given value of p MUST further enforce any additional rules for c defined by the policy referenced by p and MUST NOT produce or accept values which are not conformant with that policy’s normative requirements and semantics.

When p is set to a country code, the normative requirements and semantics regarding the presence or absence of c and the the list of values, are dependent on the specific policy of that country.

When p is set to "PUBLIC", c MUST NOT be present.

When p is set to "NATO":

  • A valid context value is always considered logically provided.

  • As such, c MUST always be present and non-empty.

  • The special STANAG 4774 context value Releasable is not encoded in the list, but is represented implicitly by the presence of a non-empty r attribute.

    As such, implementations MUST NOT produce or accept values of c containing a value of "RELEASEABLE" (in any case).

For backwards compatibility, when processing an existing Attribute Set and p is set to "NATO", an implementation MAY react to the absence of a c attribute in any of the following ways:

a) by interpreting the Attribute Set as containing an administratively specified default implied list of context values;

b) by refusing to process the Attribute Set or Message or Envelope to which it is attached.

o (only)

The o attribute corresponds to the STANAG 4774 Category element with a TagName of Only and a Type of PERMISSIVE.

It MUST NOT be present unless c is present.

Broadly speaking, o limits dissemination within the context identified by c, and as distinct from r, which represents authorized dissemination beyond that context. The exact semantics depend on the chosen value of p. However, regardless of the specific value of p, if present, it MUST be a string containing a non-empty comma separated list of uppercase values sorted in ascending lexicographic order, which conforms to the following ABNF:

  ONLY        = [O_VALUE *(',' O_VALUE)
  O_VALUE     = 1*UPPER_ALPHA *(SP 1*UPPER_ALPHA)

Regardless of the value of p, if o is present, a given value in the comma-separated list MUST NOT appear more than once.

Implementations MUST NOT produce invalid encodings of o and MUST NOT accept invalid encodings of o. Examples of invalid encodings include:

  • an encoding not matching the above ABNF (e.g. lowercase characters, trailing comma)
  • non-canonical sort order
  • duplicate values

Implementations which support a given value of p MUST further enforce any additional rules for o defined by the policy referenced by p and MUST NOT produce or accept values which are not conformant with that policy’s normative requirements and semantics.

When p is set to a country code, the normative requirements and semantics regarding the presence or absence of o and the the list of values, are dependent on the specific policy of that country.

When p is set to "PUBLIC", o MUST NOT be present.

When p is set to "NATO", the absence of the o attribute represents the absence of an “ONLY” restriction. Where present, the value specified by the o attribute MUST be valid in the context of the specific values of p and c chosen.

References

Normative References

  • BCP 14: Best Current Practice 14
  • CABE-ARCH: CABE Architecture Specification
  • Combined Communications-Electronics Board, “Data-Centric Interoperability Concepts and Design Requirements,” ACP 240(A), May 8, 2025.
  • NATO Standardization Office, “Confidentiality Metadata Label Syntax,” ADatp-4774, Ed. A, Ver. 1, Dec. 20, 2017.

Colophon

Author
Hugo Landau