id: "SC-18(05)" title: "Allow Execution Only in Confined Environments" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-18.05" priority: "P1" implementation_level: "system" parent: "SC-18" enhancement: True
Statement
Allow execution of permitted mobile code only in confined virtual machine environments.
Guidance
Permitting the execution of mobile code only in confined virtual machine environments helps prevent the introduction of malicious code into other systems and system components.
Assessment Objective
execution of permitted mobile code is allowed only in confined virtual machine environments.
System and communications protection policy
procedures addressing mobile code
mobile code usage allowances
mobile code usage restrictions
system design documentation
system configuration settings and associated documentation
list of confined virtual machine environments in which the execution of organizationally acceptable mobile code is allowed
system audit records
system security plan
other relevant documents or records
System/network administrators
organizational personnel with information security responsibilities
system developer
organizational personnel with responsibilities for managing mobile code
Mechanisms allowing for the execution of permitted mobile code in confined virtual machine environments