id: "AC-06(04)" title: "Separate Processing Domains" family: "AC" family_name: "Access Control" sort_id: "ac-06.04" priority: "P1" implementation_level: "system" parent: "AC-06" enhancement: True


Statement

Provide separate processing domains to enable finer-grained allocation of user privileges.

Guidance

Providing separate processing domains for finer-grained allocation of user privileges includes using virtualization techniques to permit additional user privileges within a virtual machine while restricting privileges to other virtual machines or to the underlying physical machine, implementing separate physical domains, and employing hardware or software domain separation mechanisms.

Assessment Objective

separate processing domains are provided to enable finer-grain allocation of user privileges.

Access control policy

procedures addressing least privilege

system design documentation

system configuration settings and associated documentation

system audit records

system security plan

other relevant documents or records

Organizational personnel with responsibilities for defining least privileges necessary to accomplish specified tasks

organizational personnel with information security responsibilities

system developers

Mechanisms implementing least privilege functions