unified
UC-NET-06 — Enforce separation with hardware and software mechanisms
Employ hardware-enforced and software-enforced separation mechanisms to isolate critical security functions and enforce policy between execution domains. Use hardware-based protections such as write-protected or read-only memory, and load and execute key programs from hardware-enforced non-modifiable media so critical code cannot be altered at runtime.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Network & Communications Security
- type
- preventive
- category
- technical
Details
- unified_id
- UC-NET-06
- title
- Enforce separation with hardware and software mechanisms
- statement
- Employ hardware-enforced and software-enforced separation mechanisms to isolate critical security functions and enforce policy between execution domains. Use hardware-based protections such as write-protected or read-only memory, and load and execute key programs from hardware-enforced non-modifiable media so critical code cannot be altered at runtime.
- domain
- Network & Communications Security
- control_type
- preventive
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- SC-49
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- SC-50
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- SC-51
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- SC-34
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-NET-06 — Enforce separation with hardware and software mechanisms maps_to SC-50 — Software-enforced Separation and Policy Enforcement
- framework
- nist-800-53
- control_id
- SC-50
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-NET-06 — Enforce separation with hardware and software mechanisms mitigates Coordinated multi-stage / APT campaigns
- strength
- related
- rationale
- Hardware/software-enforced separation of critical security functions resists implant persistence and tampering during a campaign.
- UC-NET-06 — Enforce separation with hardware and software mechanisms maps_to SC-34 — Non-modifiable Executable Programs
- framework
- nist-800-53
- control_id
- SC-34
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-NET-06 — Enforce separation with hardware and software mechanisms maps_to SC-49 — Hardware-enforced Separation and Policy Enforcement
- framework
- nist-800-53
- control_id
- SC-49
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Platform Isolation & Separation Enforcement operates UC-NET-06 — Enforce separation with hardware and software mechanisms
- UC-NET-06 — Enforce separation with hardware and software mechanisms mitigates Ransomware disrupting operations and data availability
- strength
- related
- rationale
- Hardware-enforced separation and non-modifiable executables resist ransomware tampering with and spreading through critical code.
- Security Control Assessment & POA&M Remediation tests UC-NET-06 — Enforce separation with hardware and software mechanisms
- UC-NET-06 — Enforce separation with hardware and software mechanisms maps_to SC-51 — Hardware-based Protection
- framework
- nist-800-53
- control_id
- SC-51
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-NET-06 — Enforce separation with hardware and software mechanisms mitigates Malware delivery, insertion and compromise of systems
- strength
- related
- rationale
- Non-modifiable executables and hardware write-protection resist malware tampering with critical code, but sandbox detonation (UC-NET-10) and mobile-code/web filtering (UC-NET-13) are the operative anti-malware-delivery defenses.