id: "SC-29" title: "Heterogeneity" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-29" priority: "P1" implementation_level: "organization" enhancements: - sc-29.1
Statement
Employ a diverse set of information technologies for the following system components in the implementation of the system: {{ insert: param, sc-29_odp }}.
Guidance
Increasing the diversity of information technologies within organizational systems reduces the impact of potential exploitations or compromises of specific technologies. Such diversity protects against common mode failures, including those failures induced by supply chain attacks. Diversity in information technologies also reduces the likelihood that the means adversaries use to compromise one system component will be effective against other system components, thus further increasing the adversary work factor to successfully complete planned attacks. An increase in diversity may add complexity and management overhead that could ultimately lead to mistakes and unauthorized configurations.
Assessment Objective
a diverse set of information technologies is employed for {{ insert: param, sc-29_odp }} in the implementation of the system.
System and communications protection policy
system design documentation
system configuration settings and associated documentation
list of technologies deployed in the system
acquisition documentation
acquisition contracts for system components or services
system security plan
other relevant documents or records
System/network administrators
organizational personnel with information security responsibilities
organizational personnel with system acquisition, development, and implementation responsibilities
Mechanisms supporting and/or implementing the employment of a diverse set of information technologies