id: "SC-32(01)" title: "Separate Physical Domains for Privileged Functions" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-32.01" priority: "P1" implementation_level: "system" parent: "SC-32" enhancement: True
Statement
Partition privileged functions into separate physical domains.
Guidance
Privileged functions that operate in a single physical domain may represent a single point of failure if that domain becomes compromised or experiences a denial of service.
Assessment Objective
privileged functions are partitioned into separate physical domains.
System and communications protection policy
procedures addressing system partitioning
system design documentation
system configuration settings and associated documentation
system architecture
list of system physical domains (or environments)
system facility diagrams
system network diagrams
system security plan
other relevant documents or records
System/network administrators
organizational personnel with information security responsibilities
organizational personnel installing, configuring, and/or maintaining the system
system developers/integrators
Mechanisms supporting and/or implementing the physical separation of system components