id: "SC-03(02)" title: "Access and Flow Control Functions" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-03.02" priority: "P1" implementation_level: "system" parent: "SC-03" enhancement: True
Statement
Isolate security functions enforcing access and information flow control from nonsecurity functions and from other security functions.
Guidance
Security function isolation occurs because of implementation. The functions can still be scanned and monitored. Security functions that are potentially isolated from access and flow control enforcement functions include auditing, intrusion detection, and malicious code protection functions.
Assessment Objective: security functions enforcing access control are isolated from non-security functions;
Assessment Objective: security functions enforcing access control are isolated from other security functions;
Assessment Objective: security functions enforcing information flow control are isolated from non-security functions;
Assessment Objective: security functions enforcing information flow control are isolated from other security functions.
System and communications protection policy
procedures addressing security function isolation
list of critical security functions
system design documentation
system configuration settings and associated documentation
system audit records system security plan
other relevant documents or records
System/network administrators
organizational personnel with information security responsibilities
system developer
Isolation of security functions enforcing access and information flow control