id: "SC-03(01)" title: "Hardware Separation" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-03.01" priority: "P1" implementation_level: "system" parent: "SC-03" enhancement: True


Statement

Employ hardware separation mechanisms to implement security function isolation.

Guidance

Hardware separation mechanisms include hardware ring architectures that are implemented within microprocessors and hardware-enforced address segmentation used to support logically distinct storage objects with separate attributes (i.e., readable, writeable).

Assessment Objective

hardware separation mechanisms are employed to implement security function isolation.

System and communications protection policy

procedures addressing security function isolation

system design documentation

hardware separation mechanisms

system configuration settings and associated documentation

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

system developer

Separation of security functions from non-security functions within the system