id: "SC-29" title: "Heterogeneity" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-29" priority: "P1" implementation_level: "organization" enhancements: - sc-29.1


Statement

Employ a diverse set of information technologies for the following system components in the implementation of the system: {{ insert: param, sc-29_odp }}.

Guidance

Increasing the diversity of information technologies within organizational systems reduces the impact of potential exploitations or compromises of specific technologies. Such diversity protects against common mode failures, including those failures induced by supply chain attacks. Diversity in information technologies also reduces the likelihood that the means adversaries use to compromise one system component will be effective against other system components, thus further increasing the adversary work factor to successfully complete planned attacks. An increase in diversity may add complexity and management overhead that could ultimately lead to mistakes and unauthorized configurations.

Assessment Objective

a diverse set of information technologies is employed for {{ insert: param, sc-29_odp }} in the implementation of the system.

System and communications protection policy

system design documentation

system configuration settings and associated documentation

list of technologies deployed in the system

acquisition documentation

acquisition contracts for system components or services

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

organizational personnel with system acquisition, development, and implementation responsibilities

Mechanisms supporting and/or implementing the employment of a diverse set of information technologies