Start a free trial
Menu

ADatP-4774

ADatP-4774 confidentiality metadata label syntax

Teams building or operating information systems that exchange NATO or coalition confidentiality-labelled data, and the national authorities whose security policy those labels represent

ADatP-4774 defines the XML syntax NATO uses for machine-readable confidentiality metadata labels, the digital equivalent of a paper security marking such as CONFIDENTIAL or SECRET.

Edition
A
Published
2017-12-20

What it is

A machine-readable replacement for a paper marking

Paper documents carry their security marking in a header and a footer, written by hand or by a template, in the language of whoever wrote them. That works until the same information has to move between systems, nations and coalition partners that all need to read the same marking the same way. ADatP-4774 is NATO's answer for the digital case: it defines the XML syntax for a "confidentiality metadata label", a structured piece of data that carries the same information a paper marking would, attached to a data object so that software, not a person, can decide what to do with it.

The document itself does not decide what any classification means or who is allowed to see what. It defines a container: a PolicyIdentifier naming which security policy governs the label, a mandatory Classification, an optional PrivacyMark, and a set of Category elements that refine dissemination. What those values actually mean is fixed by whichever security policy the PolicyIdentifier points to, NATO's own or a nation's. This document is not the place to look for what a classification means; it is the place to look for how that meaning gets encoded so a system can act on it.

The Allied Publication is what carries the technical content. It acquires force through STANAG 4774, the NATO Standardization Agreement. Its Letter of Promulgation states plainly: "The agreement of nations to use this publication is recorded in STANAG 4774." Nations ratify that agreement, and at least one reservation against it is recorded in the document's own front matter.

What every label has to carry

Three top-level elements carry a label: originatorConfidentialityLabel (the label the information's originator applies), alternativeConfidentialityLabel (an equivalent label in a different policy, for a different recipient) and metadataConfidentialityLabel (protecting the metadata set itself). All three share the same base structure: a mandatory ConfidentialityInformation element and a mandatory creation date, plus an optional originator identifier and an optional succession element.

Two dates matter in practice. A CreationDateTime is always required. A ReviewDateTime "SHALL be present when no SuccessionHandling element is present", so every label needs either a scheduled successor label or a manual review date attached to it, never neither. The succession mechanism itself lets an originator define a label that "will succeed the current confidentiality metadata label at the specified date and time", which is how a planned downgrade or a scheduled change in distribution is built into the label rather than actioned by a person on the day.

Categories: restrictive, permissive, informative

Beyond the classification itself, a label can carry Category elements of three distinct types, and the distinction is worth getting right because they behave differently in an access-control decision. RESTRICTIVE categories narrow who can see something (Additional Sensitivity). PERMISSIVE categories define an explicit set of recipients (Context, Only, Releasable To). INFORMATIVE categories play no part in the access decision at all (Administrative), and exist only to guide handling.

Under NATO's own security policy specifically, the document is exact about what a system has to do: "The 'Context' category MUST be present within a NATO Security Policy ConfidentialityInformation element", and it carries a single value identifying who the information was created for. Releasable To and Only are optional, and either can appear more than once where dissemination has to be extended or narrowed further. Administrative category values carry their own restriction the other way: they "are consequently valid only within ConfidentialityInformation elements that have a Classification element of 'UNCLASSIFIED'", so they cannot be attached to anything classified.

One rule is easy to miss and worth building a test for. At the highest classification, the marking a system renders does not read "NATO": the document requires that the PolicyIdentifier "MUST be displayed as 'COSMIC' instead of 'NATO'" wherever the Classification is Top Secret. A rendering routine that builds the marking straight from the PolicyIdentifier value, without this one exception, will get it wrong exactly where getting it wrong matters most.

Handling information that arrives with no label

NATO systems regularly take in information from outside sources that was never labelled at all. The document is direct about what must not happen next: the NATO security policy must not be used as that information's primary, originator label, because doing so would wrongly claim NATO ownership of something NATO did not originate. The NATO policy "can however be used in the alternative confidentiality label" instead. The primary label for unlabelled ingest uses a separate policy the document calls PUBLIC, whose single classification value is UNMARKED and whose one category, "In Confidence", is informative only.

Where it binds, and where it does not

This document addresses the people who build and operate NATO and national information systems, not a supplier directly. It speaks of "applications and services" that must be able to "create confidentiality metadata labels at any point in the information life-cycle", and of the "Governing Security Policy Authority" that fixes what a label's values mean for its own policy. A supplier meets ADatP-4774 because a system it builds or operates has to exchange labelled data with one that already implements it, most often because a contract, a tender or a national implementation directive requires it. The Scope clause points to further detail published separately: "Technical implementation of this standard will require detailed implementation profiles specific to usage scenarios" in ADatP-34.

The scheme is built to reach beyond NATO's own membership. Appendix 2 works through three example cases directly: "The example clearances consider: 1. A NATO member nation, 2. A partner nation and 3. A non-member, non-partner nation." The Context, Releasable To and Only categories exist specifically to carry that distinction into a real label.

Getting the document

ADatP-4774 is unclassified and free of charge. NATO's Standardization Document Database lists the current edition; we do not host a copy or sell it.

How we help

ADatP-4774 is an operational and technical standard, not a management-system standard, and the work it describes is systems engineering: designing the label schema into a system, choosing which security policy governs a given exchange, and generating and validating the labels themselves. That work happens in the system, not in a compliance platform.

What evidencing a labelling implementation actually involves is the paperwork around that engineering work: a procedure recording which security policy a given system or exchange uses and why, the Security Policy Information File adopted for it, training records for the people who administer or interpret labelled information, and a record that the implementation was reviewed before it went into service. ComplyTrain is where that documentation lives, gets version-controlled, and stays available for the next audit or the next system integrator who has to pick up the work. It does not write or validate the XML labels themselves, and it does not define a security policy for a nation or a programme.

Which tier of NATO documentation a given contract actually requires, and which standards sit alongside ADatP-4774 for it, is set by the contract and the customer's own quality clause. Our standards explorer shows what else typically travels with a STANAG 4774 requirement. If you are working out what a specific contract requires, talk to us.

Standards it references

Questions

Is ADatP-4774 the same thing as STANAG 4774?

No. STANAG 4774 is the NATO Standardization Agreement, the record of nations agreeing to use this publication. ADatP-4774 is the Allied Publication itself, the document that actually defines the label syntax. The agreement gives the publication its force; the publication holds the technical content.

Does ADatP-4774 tell me what my classification levels mean?

No. It defines the structure a label uses to carry a classification, a policy identifier and a set of categories, but the meaning of any specific value is fixed by whichever security policy is named in the label, NATO's own security policy or a national one, not by this document.

Can a company be certified against ADatP-4774?

No. The document defines a data syntax and names no certifying or auditing body. Conformance is technical: the schema can be validated directly, and NATO's material points to further validation languages and tools, Schematron among them, for checking that a policy's own values are used correctly.

What edition is current?

Edition A, Version 1, promulgated 20 December 2017. The document does not identify an earlier edition that it supersedes.

Does this apply to a company that is not a NATO member state?

The document's own scheme is built to travel beyond NATO membership: its example clearances specifically work through a NATO member nation, a partner nation and a non-member, non-partner nation. Whether it applies to a particular company depends on the contract or programme that company is working under, not on the document by itself.