id: "SC-02(01)" title: "Interfaces for Non-privileged Users" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-02.01" priority: "P1" implementation_level: "system" parent: "SC-02" enhancement: True
Statement
Prevent the presentation of system management functionality at interfaces to non-privileged users.
Guidance
Preventing the presentation of system management functionality at interfaces to non-privileged users ensures that system administration options, including administrator privileges, are not available to the general user population. Restricting user access also prohibits the use of the grey-out option commonly used to eliminate accessibility to such information. One potential solution is to withhold system administration options until users establish sessions with administrator privileges.
Assessment Objective
the presentation of system management functionality is prevented at interfaces to non-privileged users.
System and communications protection policy
procedures addressing application partitioning
system design documentation
system configuration settings and associated documentation
system audit records
system security plan
other relevant documents or records
System/network administrators
organizational personnel with information security responsibilities
non-privileged users of the system
system developer
Separation of user functionality from system management functionality