id: "SC-49" title: "Hardware-enforced Separation and Policy Enforcement" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-49" priority: "P1" implementation_level: "system"
Statement
Implement hardware-enforced separation and policy enforcement mechanisms between {{ insert: param, sc-49_odp }}.
Guidance
System owners may require additional strength of mechanism and robustness to ensure domain separation and policy enforcement for specific types of threats and environments of operation. Hardware-enforced separation and policy enforcement provide greater strength of mechanism than software-enforced separation and policy enforcement.
Assessment Objective
hardware-enforced separation and policy enforcement mechanisms are implemented between {{ insert: param, sc-49_odp }}.
System and communications protection policy
procedures addressing cross-domain policy enforcement
system design documentation
system configuration settings and associated documentation
system audit records
system security plan
other relevant documents or records
System/network administrators
organizational personnel with information security responsibilities
organizational personnel installing, configuring, and/or maintaining the system
Mechanisms supporting and/or implementing hardware-enforced security domain separation and policy enforcement