SC-32 System Partitioning. Partition the system into [organization-defined] residing in separate [organization-defined] domains or environments based on [organization-defined]
System Partitioning. Partition the system into [organization-defined] residing in separate [organization-defined] domains or environments based on [organization-defined].
system holds itEvidence a system already holds
- Configuration evidence that communication between partitions is restricted to defined interfaces · Cloud console / configuration management
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
- The defined system components and the separate physical or logical domains they are partitioned into · Policy repository / GRC workspace
- The defined circumstances or criteria on which the partitioning is based · Document repository
- Architecture and facility diagrams showing the partitions and the boundaries between them · Policy repository / GRC workspace
- Verification that no component spans partitions in a way that defeats the separation · Document repository
First move
Common gaps auditors find
- Partitioning at the network layer while a shared management plane or shared storage crosses every partition
- Criteria for partitioning undocumented, so new components are placed by convenience
- Partition boundaries drawn in the diagram but not enforced by configuration
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetSC-31 Covert Channel Analysis. Perform a covert channel analysis to identify those aspects of communications within the system that are potential avenues for covert [organization-defined] channels; and Estimate the maximum bandwidth of those channels · SC-34 Non-modifiable Executable Programs. For [organization-defined] , load and execute: The operating environment from hardware-enforced, read-only media; and The following applications from hardware-enforced, read-only media: [organization-defined]