unified

UC-NET-04 — Isolate system, user, and security functions

Separate user functionality, including user-interface services, from system-management functionality, and isolate security functions from non-security functions using partitioning, virtualization, or separate physical or logical components. Partition the system so components of differing sensitivity reside in separate domains, limiting the blast radius of a compromise.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Network & Communications Security
type
preventive
category
technical

Details

unified_id
UC-NET-04
title
Isolate system, user, and security functions
statement
Separate user functionality, including user-interface services, from system-management functionality, and isolate security functions from non-security functions using partitioning, virtualization, or separate physical or logical components. Partition the system so components of differing sensitivity reside in separate domains, limiting the blast radius of a compromise.
domain
Network & Communications Security
control_type
preventive
control_category
technical
members
  • framework
    nist-800-53
    control_id
    SC-2
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    SC-3
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    SC-32
    coverage
    full
    relationship
    superset_of
guidance

    Source

    No record-specific source URL is provided.

    Connections