top of page
Image of fingerprint

ACP 240: Enhancing Data-Centric Security

18/09/26, 09:00

Defence organisations are moving from security architectures built primarily around networks and applications toward Data-Centric Security (DCS), where security information travels with the data itself. Allied Communication Publication 240, or ACP 240, is an important part of that transition for Five Eyes and coalition environments.

ACP 240 is sponsored through the Combined Communications-Electronics Board (CCEB) and provides an architectural framework for improving data-centric security interoperability between allied organisations. Its significance is that it moves security closer to the information object itself, so policy can be applied consistently as information moves across applications, networks, gateways and mission-partner environments.


Why ACP 240 matters

Traditional security architectures derive much of their assurance from where information resides: a classified network, controlled repository or protected application. That model becomes harder to sustain when information must move rapidly between cloud platforms, tactical environments, coalition partners and multiple security domains.


Data-Centric Security changes the focus from “Where is the information?” to “What is the information, how sensitive is it, and who is authorised to use it?”

For that model to work, information objects need authoritative, machine-readable metadata describing attributes such as classification, releasability and handling requirements. Security controls can then use those attributes to make automated policy decisions.

ACP 240 supports this progression from machine-readable labelling through richer metadata and Attribute-Based Access Control, and ultimately toward higher-assurance protected information objects. This aligns with standards such as NATO’s STANAG 4774, which defines confidentiality metadata, and STANAG 4778, which defines mechanisms for binding metadata to data objects.


The implementation challenge

The difficulty for most defence enterprises is not defining classification policy, it is applying that policy consistently across a heterogeneous technology estate.

Email, Microsoft 365, file systems, records platforms, gateways, endpoint tools and legacy applications may all represent security metadata differently. A label that is meaningful inside one application may be opaque to another system or mission partner. Metadata can also be lost when information changes format, leaves a repository or crosses an organisational boundary.


This creates an interoperability gap: two systems can both support classification and still fail because the policy meaning, metadata representation or binding mechanism differs. The result is duplicated integration work, manual relabelling, rejected transfers and security controls making decisions from inconsistent attributes.

Janusnet’s approach is to treat metadata consistency and interoperability as enterprise security infrastructure, rather than as a feature implemented independently inside every application.


Janusnet capabilities for ACP 240 implementation

Janusnet provides capabilities across the metadata lifecycle to support defence organisations implementing Data-Centric Security and Zero Trust.


Janusseal Windows Desktop enables users to classify information as it is created, producing consistent human-readable markings and machine-readable security metadata. This helps ensure that classification and handling attributes are available to downstream systems from the point of creation.


At the endpoint, Janusnet capabilities can also normalise metadata as files are saved or downloaded, helping ensure that DLP, ABAC and other downstream security controls receive consistent attributes rather than having to interpret multiple proprietary representations.


For messaging environments, Janusgate Exchange can operate as both a Policy Decision Point and Policy Enforcement Point within the mail system. It can compare message classification attributes with recipient and destination-domain attributes to determine whether a message is permitted to be delivered. This enables automated release and delivery decisions based on the security attributes of the information itself, rather than relying only on network location or manual review.


This is particularly important in coalition and cross-domain environments, where releasability, handling caveats and destination policy must be evaluated consistently before information is released.


An incremental path to ACP 240

ACP 240 implementation does not need to be disruptive. A practical migration path is to establish machine-readable security metadata at the source:


  • normalise metadata where information enters or moves between systems;

  • expose trusted attributes to DLP, ABAC, gateways and other enforcement technologies;

  • use those trusted attributes to support higher-assurance protected exchange.


The key point is that Data-Centric Security depends on consistent metadata. If classification and handling attributes are incomplete, ambiguous or represented differently across systems, security decisions become inconsistent.


ACP 240 provides a framework for addressing that problem. Janusnet’s classification, endpoint and messaging capabilities help organisations implement that framework by making metadata consistent, machine-readable and usable by the security controls that depend on it.

bottom of page