id: "SC-07(20)" title: "Dynamic Isolation and Segregation" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-07.20" priority: "P1" implementation_level: "system" parent: "SC-07" enhancement: True
Statement
Provide the capability to dynamically isolate {{ insert: param, sc-07.20_odp }} from other system components.
Guidance
The capability to dynamically isolate certain internal system components is useful when it is necessary to partition or separate system components of questionable origin from components that possess greater trustworthiness. Component isolation reduces the attack surface of organizational systems. Isolating selected system components can also limit the damage from successful attacks when such attacks occur.
Assessment Objective
the capability to dynamically isolate {{ insert: param, sc-07.20_odp }} from other system components is provided.
System and communications protection policy
procedures addressing boundary protection
system design documentation
system hardware and software
system architecture
system configuration settings and associated documentation
list of system components to be dynamically isolated/segregated from other components of the system
system audit records
system security plan
other relevant documents or records
System/network administrators
organizational personnel with information security responsibilities
system developer
organizational personnel with boundary protection responsibilities
Mechanisms supporting and/or implementing the capability to dynamically isolate/segregate system components