id: "SC-29(01)" title: "Virtualization Techniques" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-29.01" priority: "P1" implementation_level: "organization" parent: "SC-29" enhancement: True


Statement

Employ virtualization techniques to support the deployment of a diversity of operating systems and applications that are changed {{ insert: param, sc-29.01_odp }}.

Guidance

While frequent changes to operating systems and applications can pose significant configuration management challenges, the changes can result in an increased work factor for adversaries to conduct successful attacks. Changing virtual operating systems or applications, as opposed to changing actual operating systems or applications, provides virtual changes that impede attacker success while reducing configuration management efforts. Virtualization techniques can assist in isolating untrustworthy software or software of dubious provenance into confined execution environments.

Assessment Objective

virtualization techniques are employed to support the deployment of a diverse range of operating systems and applications that are changed {{ insert: param, sc-29.01_odp }}.

System and communications protection policy

configuration management policy and procedures

system design documentation

system configuration settings and associated documentation

system architecture

list of operating systems and applications deployed using virtualization techniques

change control records

configuration management records

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

organizational personnel with responsibilities for implementing approved virtualization techniques to the system

Mechanisms supporting and/or implementing the employment of a diverse set of information technologies

mechanisms supporting and/or implementing virtualization techniques