id: "SC-07(20)" title: "Dynamic Isolation and Segregation" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-07.20" priority: "P1" implementation_level: "system" parent: "SC-07" enhancement: True


Statement

Provide the capability to dynamically isolate {{ insert: param, sc-07.20_odp }} from other system components.

Guidance

The capability to dynamically isolate certain internal system components is useful when it is necessary to partition or separate system components of questionable origin from components that possess greater trustworthiness. Component isolation reduces the attack surface of organizational systems. Isolating selected system components can also limit the damage from successful attacks when such attacks occur.

Assessment Objective

the capability to dynamically isolate {{ insert: param, sc-07.20_odp }} from other system components is provided.

System and communications protection policy

procedures addressing boundary protection

system design documentation

system hardware and software

system architecture

system configuration settings and associated documentation

list of system components to be dynamically isolated/segregated from other components of the system

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

system developer

organizational personnel with boundary protection responsibilities

Mechanisms supporting and/or implementing the capability to dynamically isolate/segregate system components