id: "SC-32(01)" title: "Separate Physical Domains for Privileged Functions" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-32.01" priority: "P1" implementation_level: "system" parent: "SC-32" enhancement: True


Statement

Partition privileged functions into separate physical domains.

Guidance

Privileged functions that operate in a single physical domain may represent a single point of failure if that domain becomes compromised or experiences a denial of service.

Assessment Objective

privileged functions are partitioned into separate physical domains.

System and communications protection policy

procedures addressing system partitioning

system design documentation

system configuration settings and associated documentation

system architecture

list of system physical domains (or environments)

system facility diagrams

system network diagrams

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

organizational personnel installing, configuring, and/or maintaining the system

system developers/integrators

Mechanisms supporting and/or implementing the physical separation of system components