id: "SC-04(02)" title: "Multilevel or Periods Processing" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-04.02" priority: "P1" implementation_level: "system" parent: "SC-04" enhancement: True


Statement

Prevent unauthorized information transfer via shared resources in accordance with {{ insert: param, sc-04.02_odp }} when system processing explicitly switches between different information classification levels or security categories.

Guidance

Changes in processing levels can occur during multilevel or periods processing with information at different classification levels or security categories. It can also occur during serial reuse of hardware components at different classification levels. Organization-defined procedures can include approved sanitization processes for electronically stored information.

Assessment Objective

unauthorized information transfer via shared resources is prevented in accordance with {{ insert: param, sc-04.02_odp }} when system processing explicitly switches between different information classification levels or security categories.

System and communications protection policy

procedures addressing information protection in shared system resources

system design documentation

system configuration settings and associated documentation

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

system developer

Mechanisms preventing the unauthorized transfer of information via shared system resources