Skip to content

Evidence request lists

NATO STANAG 4774 (Confidentiality Metadata Labels) and STANAG 4778 (Metadata Binding)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Application Handling

STANAG-6
Label Handling in Email, Documents, and Storage

Implement STANAG 4774/4778 label handling across email per RFC 8551 S/MIME + RFC 9580 OpenPGP profiles, documents per OOXML/ODF embedded metadata + PDF/X-3 embedded XML, file storage per NTFS/EXT4 extended attributes + cloud object storage tags. Configure email gateways (Microsoft Exchange + Postfix + Sendmail + Cisco IronPort + Proofpoint + Mimecast) to verify + filter + route based on STANAG labels. Configure document management systems (SharePoint + OpenText + IBM Filenet + Documentum) to enforce label-based access control + retention.

Artefacts an auditor will ask for
  • Email gateway configuration
  • Document management system integration
  • Storage attribute mapping
  • S/MIME profile compliance
  • OOXML/PDF embedded label samples
  • Cloud tag mapping
Where this commonly fails
  • Email gateway not configured
  • Documents missing labels
  • Storage attributes lost
  • No cloud tag mapping

Caveats and Releasability

STANAG-8
Label Caveats, Releasability, and Conditions

Apply STANAG 4774 caveats (NOFORN + REL TO + EYES ONLY + LIMDIS + ORCON + SI + TK + HCS + KLONDIKE + national caveats) and releasability markings (REL TO countries) per the originator security policy. Apply STANAG 4774 conditions (compartment + sub-compartment + handling instructions + dissemination controls + special handling). Validate caveat compatibility before any release decision. Enforce caveat-based access control through Attribute Based Access Control (ABAC) systems integrated with STANAG 4778 bound labels.

Artefacts an auditor will ask for
  • Caveat code register
  • Releasability matrix
  • ABAC policy integration
  • Release decision logs
  • Caveat compatibility validation
  • Special compartment handling procedures
Where this commonly fails
  • Missing caveat codes
  • No releasability matrix
  • No ABAC integration
  • Unvalidated release decisions

Cross-Domain Solutions

STANAG-4
Cross-Domain Label Translation and Interoperability Testing

Implement cross-domain label translation between NATO and national classification systems via Cross Domain Solution (CDS) capable of parsing + validating + translating STANAG 4774 labels across security domains. Conduct interoperability testing using NATO Interoperability Standards and Profiles (NISP) test cases + Coalition Warrior Interoperability eXploration Experimentation Examination Exercise (CWIX) + Bold Quest joint exercises. Coordinate with NATO Information Exchange Gateway Service (IEGS) for low-side to high-side data transfers per AC/322(SC/4)WP(2018) Cross Domain Solutions Policy.

Artefacts an auditor will ask for
  • CDS deployment authorisation
  • NISP test case results
  • CWIX participation evidence
  • Bold Quest participation
  • Translation rule sets
  • IEGS coordination records
Where this commonly fails
  • No CDS authorisation
  • Missing NISP testing
  • No CWIX participation
  • Incomplete translation rules

Label Authoring

STANAG-3
Label Authoring, Originator Identification, and Policy Identifier

Provide approved label authoring tools that produce STANAG 4774 compliant labels including originator identification (distinguished name + originator identifier per ITU-T X.509), policy identifier referencing the applicable national or NATO security policy, and policy version. Approved tools: Boldon James Classifier + TITUS Classification + Janusseal + Cysec + Microsoft Information Protection (with NATO connector) + Open Source Information Labelling System (OSILS) + STANAG 4778 reference implementations. Train users in correct label application per AC/322(SC/4)WP(2019)0001 NATO Labelling Guidance.

Artefacts an auditor will ask for
  • Approved tool inventory
  • Tool deployment records
  • Originator distinguished name register
  • Security policy register
  • Policy version tracking
  • User training records
Where this commonly fails
  • Unapproved tools
  • Missing originator DN
  • Outdated policy reference
  • No user training

Label Lifecycle

STANAG-5
Label Verification on Ingress and Label Preservation Through Processing

Verify confidentiality label authenticity and integrity on data ingress per STANAG 4778 binding verification. Reject or quarantine data with invalid + corrupted + unrecognised labels. Preserve labels throughout processing including data transformation + extract-transform-load (ETL) operations + analytics pipelines + content delivery. Apply label inheritance rules to derivative products (highest contributing label rule per NATO Security Policy). Maintain audit trails of label preservation through processing pipelines.

Artefacts an auditor will ask for
  • Ingress verification logic deployment
  • Quarantine procedures
  • Label preservation in ETL pipelines
  • Inheritance rule documentation
  • Audit trails of label evolution
  • Derivative product labelling
Where this commonly fails
  • No ingress verification
  • Lost labels through processing
  • Wrong inheritance rule
  • No audit trail

Label Schema

STANAG-1
STANAG 4774 Confidentiality Label Schema and XML Structure

Adopt the NATO STANAG 4774 (Confidentiality Metadata Label) XML schema as the canonical confidentiality labelling format for classified and protectively marked information. Implement the OriginatorConfidentialityLabel + AlternativeConfidentialityLabel + Classification + ClassificationCategories + Caveats + Releasability + Releasability+ Conditions XML elements per the published XML Schema Definition (XSD). Map national classification systems (US NOFORN/SECRET/TS + UK OFFICIAL-SENSITIVE/SECRET/TOP-SECRET + DE VS-NfD/GEHEIM + FR DR/CD/SD/TSD + EU RESTREINT-UE/CONFIDENTIEL-UE/SECRET-UE) into STANAG 4774 classification equivalents.

Artefacts an auditor will ask for
  • STANAG 4774 XSD adoption record
  • XML validation tooling deployment
  • National classification mapping matrix
  • Sample compliant labels
  • Schema version tracking
Where this commonly fails
  • No XSD validation
  • Missing classification mapping
  • Outdated schema version
  • No sample compliance

Metadata Binding

STANAG-2
STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding

Apply STANAG 4778 metadata binding to associate STANAG 4774 confidentiality labels with the data they describe via cryptographic binding using XML Digital Signatures (XML-DSig) per W3C XMLDSIG-CORE specification. Use the STANAG 4778 BoundConfidentialityLabel + MetadataBindingContainer + DataObjectReference elements. Implement supported binding profiles: Enveloped + Enveloping + Detached + Email (RFC 8551 S/MIME). Use cryptographic algorithms per CNSA Suite 1.0 / 2.0 (RSA-3072 + ECDSA P-384 + SHA-384 + AES-256-GCM) or national equivalents.

Artefacts an auditor will ask for
  • STANAG 4778 binding implementation
  • XML-DSig validation
  • Binding profile inventory
  • CNSA Suite algorithm compliance
  • Sample bound containers
  • Key management procedures
Where this commonly fails
  • No binding mechanism
  • Outdated algorithms
  • Missing profile coverage
  • No key management

Operations and Training

STANAG-7
Incident Response, User Training, and Label Audit

Establish incident response procedures for label failures including incorrect labelling + over-classification + under-classification + label loss in transit + label corruption. Conduct annual user training covering STANAG 4774 label structure + 4778 binding + correct application + caveats + releasability + common errors. Audit label application accuracy + completeness + currency on at least an annual basis with statistical sampling. Report aggregate metrics to the Information Assurance Officer + NATO Information Assurance Authority (INFOSEC).

Artefacts an auditor will ask for
  • Label failure IR procedures
  • Annual training programme
  • Training completion records
  • Annual audit reports
  • Statistical sampling methodology
  • INFOSEC reporting
Where this commonly fails
  • No IR for label failures
  • No annual training
  • Missing audit reports
  • No INFOSEC reporting
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NATO STANAG 4774 (Confidentiality Metadata Labels) and STANAG 4778 (Metadata Binding) framework page.