CCI-001086
CCI-001086 Definition
| Status | |
| Type | CheckType.technical |
Master Assessment Datasheet
Implementation Guidance
Determine if: - security functions enforcing access control are isolated from non-security functions. - security functions enforcing access control are isolated from other security functions. - security functions enforcing information flow control are isolated from non-security functions. - security functions enforcing information flow control are isolated from other security functions.
Validation Procedures
Examine: [SELECT FROM: System and communications protection policy; procedures addressing security function isolation; list of critical security functions; system design documentation; system configuration settings and associated documentation; system audit records system security plan; other relevant documents or records]. Interview: [SELECT FROM: System/network administrators; organizational personnel with information security responsibilities; system developer]. Test: [SELECT FROM: Isolation of security functions enforcing access and information flow control].