id: "SC-03(02)" title: "Access and Flow Control Functions" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-03.02" priority: "P1" implementation_level: "system" parent: "SC-03" enhancement: True


Statement

Isolate security functions enforcing access and information flow control from nonsecurity functions and from other security functions.

Guidance

Security function isolation occurs because of implementation. The functions can still be scanned and monitored. Security functions that are potentially isolated from access and flow control enforcement functions include auditing, intrusion detection, and malicious code protection functions.

Assessment Objective: security functions enforcing access control are isolated from non-security functions;

Assessment Objective: security functions enforcing access control are isolated from other security functions;

Assessment Objective: security functions enforcing information flow control are isolated from non-security functions;

Assessment Objective: security functions enforcing information flow control are isolated from other security functions.

System and communications protection policy

procedures addressing security function isolation

list of critical security functions

system design documentation

system configuration settings and associated documentation

system audit records system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

system developer

Isolation of security functions enforcing access and information flow control