Device Class 1: Application Partitioning

Control ID: SC-2 Application Partitioning Family: System and Communications Protection Source: NIST 800-53r4
Control: The information system separates user functionality (including user interface services) from information system management functionality.
Supplemental Guidance:
Information system management functionality includes, for example, functions necessary to administer databases, network components, workstations, or servers, and typically requires privileged user access. The separation of user functionality from information system management functionality is either physical or logical. Organizations implement separation of system management-related functionality from user functionality by using different computers, different central processing units, different instances of operating systems, different network addresses, virtualization techniques, or combinations of these or other methods, as appropriate. This type of separation includes, for example, web administrative interfaces that use separate authentication methods for users of any other information system resources. Separation of system and user functionality may include isolating administrative interfaces on different domains and with additional access controls.

Related Controls: SA-4, SA-8, SC-3
Control Enhancements: N/A
References: N/A
Mechanisms:

  • The device shall separate system management functionality from user application functionality by implementing all of the following:
    • The device requires an authentication mechanism for system management that is not used for any other function.
    • The device requires system management functions use memory that is either :
      • Dedicated exclusively to system management functions, or
      • Allocated dynamically to system management functions and not shared with non-management functions once allocated.
      See also SC-39.

Protocol Implementation Conformance Statements:
ID Statement Status Reference Notes
SC-2/1 Provides system Management authentication mechanism separate from non-management functions SC-2/1: O1
SC-2/2.1 Supports System Management dedicated memory SC-2/2: O1
SC-2/2.2 Supports System Management non-shared dynamic memory access SC-2-2/:O1