Separate Physical Domains for Privileged Functions
LOW MODERATE HIGHRequirements NIST SOURCE
Partition privileged functions into separate physical domains.
Discussion (NIST Supplemental Guidance)
Privileged functions that operate in a single physical domain may represent a single point of failure if that domain becomes compromised or experiences a denial of service.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for SC-32(1) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- privileged functions are partitioned into separate physical domains.
Examine
[SELECT FROM: System and communications protection policy; procedures addressing system partitioning; system design documentation; system configuration settings and associated documentation; system architecture; list of system physical domains (or environments); system facility diagrams; system network diagrams; system security plan; other relevant documents or records].
Interview
[SELECT FROM: System/network administrators; organizational personnel with information security responsibilities; organizational personnel installing, configuring, and/or maintaining the system; system developers/integrators].
Test
[SELECT FROM: Mechanisms supporting and/or implementing the physical separation of system components].
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for SC-32(1). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- System and communications protection policy
- system security plan
Configuration
- system design documentation
- system configuration settings and associated documentation
- system architecture
Testing
- Mechanisms supporting and/or implementing the physical separation of system components
Other Records
- procedures addressing system partitioning
- list of system physical domains (or environments)
- system facility diagrams
- system network diagrams
- other relevant documents or records