800-53|AC-6(4)

Title

SEPARATE PROCESSING DOMAINS

Description

The information system provides separate processing domains to enable finer-grained allocation of user privileges.

Supplemental

Providing separate processing domains for finer-grained allocation of user privileges includes, for example: (i) using virtualization techniques to allow additional privileges within a virtual machine while restricting privileges to other virtual machines or to the underlying actual machine; (ii) employing hardware and/or software domain separation mechanisms; and (iii) implementing separate physical domains.

Reference Item Details

Related: AC-4,SC-3,SC-30,SC-32

Category: ACCESS CONTROL

Parent Title: LEAST PRIVILEGE

Family: ACCESS CONTROL

Audit Items