Introduction
This document specifies the NATO ACP240 Attribute Mapping. It comprises one of the additional specifications of the CABE Architecture, as defined in the CABE Architecture Specification.
The CABE Architecture defines the concept of an Attribute Set, which is a set of key value pairs characterising a CABE Message or CABE Envelope. This document defines an attribute mapping aligned with the NATO ACP240 architecture and and the STANAG 4774 labelling scheme.
Definitions
The key words “MUST”, “MUST NOT”, “REQUIRED”, “SHALL”, “SHALL NOT”, “SHOULD”, “SHOULD NOT”, “RECOMMENDED”, “NOT RECOMMENDED”, “MAY” and “OPTIONAL” in this document are to be interpreted as specified in BCP 14 when, and only when, they appear in all capitals, as shown here.
All definitions given in the CABE Architecture Specification are reused for the purposes of this document.
Scope
This document defines a mapping for a subset of the full NATO ACP240 / STANAG 4774 classification taxonomy.
Defined Attributes
p (policyIdentifier)
The p attribute corresponds to the STANAG 4774 policyIdentifier field.
It MUST be present and MUST conform to the following ABNF:
POLICY_IDENTIFIER = COUNTRY / "NATO" / "PUBLIC"
COUNTRY = 3UPPER_ALPHA
UPPER_ALPHA = %x41-5A
s (sensitivity)
The s attribute corresponds to the STANAG 4774 classification
field. It MUST be present. The values for this field MUST be uppercase.
When p is set to "NATO" it MUST be set to one of the following values:
"UNCLASSIFIED""RESTRICTED""CONFIDENTIAL""SECRET""TOP SECRET"
When p is set to "PUBLIC", it MUST be set to "UNMARKED".
When p is set to a country code, the valid values are dependent on the
specific policy of that country.
r (releasability)
The r attribute corresponds to the STANAG 4774 releasability field. It MAY
be present. If present, it MUST be a string containing a comma separated list
of uppercase values sorted in ascending lexicographic order. A given value MUST
NOT appear twice. The list MAY be empty, in which case it is represented as the
empty string.
These requirements are intended to create a canonical representation for a logical set of country codes.
Values MUST conform to the following ABNF.
# List must be sorted in ascending lexicographic order
# List must not contain duplicates
R_VALUE = [R_ITEM *(',' R_ITEM)]
R_ITEM = SPECIAL_GROUP / COUNTRY
SPECIAL_GROUP = 1*(UPPER_ALPHA / SP)
# COUNTRY, UPPER_ALPHA are defined as under `p`
c (context)
The c attribute corresponds to the STANAG 4774 Category element with a
TagName of Context and a Type of PERMISSIVE.
The exact semantics depend on the chosen value of p. However, regardless of
the specific value of p, if present, it MUST be a string containing a
(possibly empty) comma separated list of uppercase values sorted in ascending
lexicographic order, which conforms to the following ABNF:
CONTEXT = [C_VALUE *(',' C_VALUE)
C_VALUE = 1*UPPER_ALPHA *(SP 1*UPPER_ALPHA)
Regardless of the value of p, if c is present, a given value in the
comma-separated list MUST NOT appear more than once.
Implementations MUST NOT produce invalid encodings of c and MUST NOT accept
invalid encodings of c. Examples of invalid encodings include:
- an encoding not matching the above ABNF (e.g. lowercase characters, trailing comma)
- non-canonical sort order
- duplicate values
Implementations which support a given value of p MUST further enforce any
additional rules for c defined by the policy referenced by p and MUST NOT
produce or accept values which are not conformant with that policy’s normative
requirements and semantics.
When p is set to a country code, the normative requirements and semantics
regarding the presence or absence of c and the the list of values, are
dependent on the specific policy of that country.
When p is set to "PUBLIC", c MUST NOT be present.
When p is set to "NATO":
-
A valid context value is always considered logically provided.
-
As such,
cMUST always be present and non-empty. -
The special STANAG 4774 context value
Releasableis not encoded in the list, but is represented implicitly by the presence of a non-emptyrattribute.As such, implementations MUST NOT produce or accept values of
ccontaining a value of"RELEASEABLE"(in any case).
For backwards compatibility, when processing an existing Attribute Set and p
is set to "NATO", an implementation MAY react to the absence of a c
attribute in any of the following ways:
a) by interpreting the Attribute Set as containing an administratively specified default implied list of context values;
b) by refusing to process the Attribute Set or Message or Envelope to which it is attached.
o (only)
The o attribute corresponds to the STANAG 4774 Category element with a
TagName of Only and a Type of PERMISSIVE.
It MUST NOT be present unless c is present.
Broadly speaking, o limits dissemination within the context identified by
c, and as distinct from r, which represents authorized dissemination beyond
that context. The exact semantics depend on the chosen value of p. However,
regardless of the specific value of p, if present, it MUST be a string
containing a non-empty comma separated list of uppercase values sorted in
ascending lexicographic order, which conforms to the following ABNF:
ONLY = [O_VALUE *(',' O_VALUE)
O_VALUE = 1*UPPER_ALPHA *(SP 1*UPPER_ALPHA)
Regardless of the value of p, if o is present, a given value in the
comma-separated list MUST NOT appear more than once.
Implementations MUST NOT produce invalid encodings of o and MUST NOT accept
invalid encodings of o. Examples of invalid encodings include:
- an encoding not matching the above ABNF (e.g. lowercase characters, trailing comma)
- non-canonical sort order
- duplicate values
Implementations which support a given value of p MUST further enforce any
additional rules for o defined by the policy referenced by p and MUST NOT
produce or accept values which are not conformant with that policy’s normative
requirements and semantics.
When p is set to a country code, the normative requirements and semantics
regarding the presence or absence of o and the the list of values, are
dependent on the specific policy of that country.
When p is set to "PUBLIC", o MUST NOT be present.
When p is set to "NATO", the absence of the o attribute represents the
absence of an “ONLY” restriction. Where present, the value specified by the o
attribute MUST be valid in the context of the specific values of p and c
chosen.
References
Normative References
- BCP 14: Best Current Practice 14
- CABE-ARCH: CABE Architecture Specification
- Combined Communications-Electronics Board, “Data-Centric Interoperability Concepts and Design Requirements,” ACP 240(A), May 8, 2025.
- NATO Standardization Office, “Confidentiality Metadata Label Syntax,” ADatp-4774, Ed. A, Ver. 1, Dec. 20, 2017.
Colophon
Author
Hugo Landau