{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Network & Communications Security","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-NET-06","description":"Employ hardware-enforced and software-enforced separation mechanisms to isolate critical security functions and enforce policy between execution domains. Use hardware-based protections such as write-protected or read-only memory, and load and execute key programs from hardware-enforced non-modifiable media so critical code cannot be altered at runtime.","details":{"control_category":"technical","control_type":"preventive","domain":"Network & Communications Security","guidance":[],"members":[{"control_id":"SC-49","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SC-50","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SC-51","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SC-34","coverage":"full","framework":"nist-800-53","relationship":"superset_of"}],"statement":"Employ hardware-enforced and software-enforced separation mechanisms to isolate critical security functions and enforce policy between execution domains. Use hardware-based protections such as write-protected or read-only memory, and load and execute key programs from hardware-enforced non-modifiable media so critical code cannot be altered at runtime.","title":"Enforce separation with hardware and software mechanisms","unified_id":"UC-NET-06"},"id":"uc:UC-NET-06","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-NET-06","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"UC-NET-06 — Enforce separation with hardware and software mechanisms","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:32d68072a0f92191b93dcb53a510c65c9763759e2948b618988fbb5d56883163","properties":{"control_id":"SC-50","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-06-f006626f.json","sourceId":"uc:UC-NET-06","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-50-29a012aa.json","targetId":"ctrl:nist-800-53:SC-50","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:38173739b599c45e79e6a42539344dc60fdd459595320bbd50b2202a8f20fe8a","properties":{"rationale":"Hardware/software-enforced separation of critical security functions resists implant persistence and tampering during a campaign.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-net-06-f006626f.json","sourceId":"uc:UC-NET-06","targetDetailPath":"/data/v1/records/risk-cyber-coordinated-campaign-b5879769.json","targetId":"risk:cyber-coordinated-campaign","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4c5165320bb23bc3f3214a6edc9e5044988867f3cadb59fc75998cdcc28698bb","properties":{"control_id":"SC-34","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-06-f006626f.json","sourceId":"uc:UC-NET-06","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-34-01dba475.json","targetId":"ctrl:nist-800-53:SC-34","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8b6606dcb94279b9f7a4db7b18b4fd570628067f85c3a0e8c17012815bf215b4","properties":{"control_id":"SC-49","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-06-f006626f.json","sourceId":"uc:UC-NET-06","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-49-eedaea3a.json","targetId":"ctrl:nist-800-53:SC-49","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:94c26cfd5dead60f6a061a1d76c189d2f8243601d9889b4b066291ae1cc8793d","properties":{},"sourceDetailPath":"/data/v1/records/wf-c50-4402d67a.json","sourceId":"wf:C50","targetDetailPath":"/data/v1/records/uc-uc-net-06-f006626f.json","targetId":"uc:UC-NET-06","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c21783fc09d54611907bb103862ddfdb2438c2ff11698ba1a2300b79fb97c033","properties":{"rationale":"Hardware-enforced separation and non-modifiable executables resist ransomware tampering with and spreading through critical code.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-net-06-f006626f.json","sourceId":"uc:UC-NET-06","targetDetailPath":"/data/v1/records/risk-sdlc-ransomware-32ab67f4.json","targetId":"risk:sdlc-ransomware","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d91728f3d689a07f0790923a0d03bea4427ebece4bbbc31f0295aaf2be6001ff","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-net-06-f006626f.json","targetId":"uc:UC-NET-06","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e40d26f83732a96b95248e76198c68de32b3af4fa9babb20021e2bee5bdead8f","properties":{"control_id":"SC-51","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-06-f006626f.json","sourceId":"uc:UC-NET-06","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-51-ad2a77f0.json","targetId":"ctrl:nist-800-53:SC-51","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ffa21717c7b536b311576189f5ac36f3574b198353d58226190a8bc3f716acb6","properties":{"rationale":"Non-modifiable executables and hardware write-protection resist malware tampering with critical code, but sandbox detonation (UC-NET-10) and mobile-code/web filtering (UC-NET-13) are the operative anti-malware-delivery defenses.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-net-06-f006626f.json","sourceId":"uc:UC-NET-06","targetDetailPath":"/data/v1/records/risk-sdlc-malware-injection-compromise-ec5a8dc4.json","targetId":"risk:sdlc-malware-injection-compromise","type":"mitigates"}],"schemaVersion":1}
