id: "AC-06(04)" title: "Separate Processing Domains" family: "AC" family_name: "Access Control" sort_id: "ac-06.04" priority: "P1" implementation_level: "system" parent: "AC-06" enhancement: True
Statement
Provide separate processing domains to enable finer-grained allocation of user privileges.
Guidance
Providing separate processing domains for finer-grained allocation of user privileges includes using virtualization techniques to permit additional user privileges within a virtual machine while restricting privileges to other virtual machines or to the underlying physical machine, implementing separate physical domains, and employing hardware or software domain separation mechanisms.
Assessment Objective
separate processing domains are provided to enable finer-grain allocation of user privileges.
Access control policy
procedures addressing least privilege
system design documentation
system configuration settings and associated documentation
system audit records
system security plan
other relevant documents or records
Organizational personnel with responsibilities for defining least privileges necessary to accomplish specified tasks
organizational personnel with information security responsibilities
system developers
Mechanisms implementing least privilege functions