EvidenceSheet

SC-2 Separation of system and user functionality

Requires user functionality, including user interface services, to be kept separate from system management functionality so that ordinary use of the system does not expose administrative interfaces and capabilities.

4
artefacts
1
held by a system
1
at each review
moderate
to go live
Cloud console / configuration management
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Configuration evidence such as separate management interfaces, networks or hosts · Cloud console / configuration management

periodic reviewEvidence produced at each review

  • Test results confirming management functions are not exposed to ordinary users · Source control / CI pipeline

governing documentDocuments that govern the control

  • Architecture documentation showing separation of user and management planes · Policy repository / GRC workspace
  • Access control showing administrative functions are unreachable from user contexts · Policy repository / GRC workspace

First move

Start with the 1 of 4 artefacts that already live in a system (Cloud console / configuration management); keep the periodic reviews but log each one as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

SC-1 Policy and procedures for system and communications protection · SC-3 Security Function Isolation. Isolate security functions from nonsecurity functions