SC-2 Separation of system and user functionality
Requires user functionality, including user interface services, to be kept separate from system management functionality so that ordinary use of the system does not expose administrative interfaces and capabilities.
4
artefacts
1
held by a system
1
at each review
moderate
to go live
Cloud console / configuration management
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Configuration evidence such as separate management interfaces, networks or hosts · Cloud console / configuration management
periodic reviewEvidence produced at each review
- Test results confirming management functions are not exposed to ordinary users · Source control / CI pipeline
governing documentDocuments that govern the control
- Architecture documentation showing separation of user and management planes · Policy repository / GRC workspace
- Access control showing administrative functions are unreachable from user contexts · Policy repository / GRC workspace
First move
Start with the 1 of 4 artefacts that already live in a system (Cloud console / configuration management); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Administrative console served from the same interface and address as the user application
- Management network reachable from the general user network
- Separation designed but broken by a convenience path added later
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetSC-1 Policy and procedures for system and communications protection · SC-3 Security Function Isolation. Isolate security functions from nonsecurity functions