id: "SC-02(01)" title: "Interfaces for Non-privileged Users" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-02.01" priority: "P1" implementation_level: "system" parent: "SC-02" enhancement: True


Statement

Prevent the presentation of system management functionality at interfaces to non-privileged users.

Guidance

Preventing the presentation of system management functionality at interfaces to non-privileged users ensures that system administration options, including administrator privileges, are not available to the general user population. Restricting user access also prohibits the use of the grey-out option commonly used to eliminate accessibility to such information. One potential solution is to withhold system administration options until users establish sessions with administrator privileges.

Assessment Objective

the presentation of system management functionality is prevented at interfaces to non-privileged users.

System and communications protection policy

procedures addressing application partitioning

system design documentation

system configuration settings and associated documentation

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

non-privileged users of the system

system developer

Separation of user functionality from system management functionality