unified
UC-NET-04 — Isolate system, user, and security functions
Separate user functionality, including user-interface services, from system-management functionality, and isolate security functions from non-security functions using partitioning, virtualization, or separate physical or logical components. Partition the system so components of differing sensitivity reside in separate domains, limiting the blast radius of a compromise.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Network & Communications Security
- type
- preventive
- category
- technical
Details
- unified_id
- UC-NET-04
- title
- Isolate system, user, and security functions
- statement
- Separate user functionality, including user-interface services, from system-management functionality, and isolate security functions from non-security functions using partitioning, virtualization, or separate physical or logical components. Partition the system so components of differing sensitivity reside in separate domains, limiting the blast radius of a compromise.
- domain
- Network & Communications Security
- control_type
- preventive
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- SC-2
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- SC-3
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- SC-32
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-NET-04 — Isolate system, user, and security functions mitigates Cloud multi-tenancy isolation and data-scavenging exploits
- strength
- related
- rationale
- Partitioning components of differing sensitivity into separate domains reinforces the isolation a multi-tenancy exploit tries to violate.
- UC-NET-04 — Isolate system, user, and security functions maps_to SC-32 — System Partitioning
- framework
- nist-800-53
- control_id
- SC-32
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-NET-04 — Isolate system, user, and security functions mitigates Coordinated multi-stage / APT campaigns
- strength
- related
- rationale
- Isolating functions and partitioning domains limits an adversary's lateral movement and progression across systems.
- UC-NET-04 — Isolate system, user, and security functions maps_to SC-2 — Separation of System and User Functionality
- framework
- nist-800-53
- control_id
- SC-2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Platform Isolation & Separation Enforcement operates UC-NET-04 — Isolate system, user, and security functions
- UC-NET-04 — Isolate system, user, and security functions maps_to SC-3 — Security Function Isolation
- framework
- nist-800-53
- control_id
- SC-3
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Security Control Assessment & POA&M Remediation tests UC-NET-04 — Isolate system, user, and security functions
- UC-NET-04 — Isolate system, user, and security functions mitigates Ransomware disrupting operations and data availability
- strength
- primary
- rationale
- Partitioning the system into separate domains of differing sensitivity limits ransomware lateral spread and blast radius (mustKeep).
- Technical Security Testing & Pentest Engagement tests UC-NET-04 — Isolate system, user, and security functions