id: "SC-18(05)" title: "Allow Execution Only in Confined Environments" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-18.05" priority: "P1" implementation_level: "system" parent: "SC-18" enhancement: True


Statement

Allow execution of permitted mobile code only in confined virtual machine environments.

Guidance

Permitting the execution of mobile code only in confined virtual machine environments helps prevent the introduction of malicious code into other systems and system components.

Assessment Objective

execution of permitted mobile code is allowed only in confined virtual machine environments.

System and communications protection policy

procedures addressing mobile code

mobile code usage allowances

mobile code usage restrictions

system design documentation

system configuration settings and associated documentation

list of confined virtual machine environments in which the execution of organizationally acceptable mobile code is allowed

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

system developer

organizational personnel with responsibilities for managing mobile code

Mechanisms allowing for the execution of permitted mobile code in confined virtual machine environments