id: "SC-49" title: "Hardware-enforced Separation and Policy Enforcement" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-49" priority: "P1" implementation_level: "system"


Statement

Implement hardware-enforced separation and policy enforcement mechanisms between {{ insert: param, sc-49_odp }}.

Guidance

System owners may require additional strength of mechanism and robustness to ensure domain separation and policy enforcement for specific types of threats and environments of operation. Hardware-enforced separation and policy enforcement provide greater strength of mechanism than software-enforced separation and policy enforcement.

Assessment Objective

hardware-enforced separation and policy enforcement mechanisms are implemented between {{ insert: param, sc-49_odp }}.

System and communications protection policy

procedures addressing cross-domain policy enforcement

system design documentation

system configuration settings and associated documentation

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

organizational personnel installing, configuring, and/or maintaining the system

Mechanisms supporting and/or implementing hardware-enforced security domain separation and policy enforcement