id: "SC-04(02)" title: "Multilevel or Periods Processing" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-04.02" priority: "P1" implementation_level: "system" parent: "SC-04" enhancement: True
Statement
Prevent unauthorized information transfer via shared resources in accordance with {{ insert: param, sc-04.02_odp }} when system processing explicitly switches between different information classification levels or security categories.
Guidance
Changes in processing levels can occur during multilevel or periods processing with information at different classification levels or security categories. It can also occur during serial reuse of hardware components at different classification levels. Organization-defined procedures can include approved sanitization processes for electronically stored information.
Assessment Objective
unauthorized information transfer via shared resources is prevented in accordance with {{ insert: param, sc-04.02_odp }} when system processing explicitly switches between different information classification levels or security categories.
System and communications protection policy
procedures addressing information protection in shared system resources
system design documentation
system configuration settings and associated documentation
system audit records
system security plan
other relevant documents or records
System/network administrators
organizational personnel with information security responsibilities
system developer
Mechanisms preventing the unauthorized transfer of information via shared system resources