800-53|SC-2

Title

APPLICATION PARTITIONING

Description

The information system separates user functionality (including user interface services) from information system management functionality.

Supplemental

Information system management functionality includes, for example, functions necessary to administer databases, network components, workstations, or servers, and typically requires privileged user access. The separation of user functionality from information system management functionality is either physical or logical. Organizations implement separation of system management-related functionality from user functionality by using different computers, different central processing units, different instances of operating systems, different network addresses, virtualization techniques, or combinations of these or other methods, as appropriate. This type of separation includes, for example, web administrative interfaces that use separate authentication methods for users of any other information system resources. Separation of system and user functionality may include isolating administrative interfaces on different domains and with additional access controls.

Reference Item Details

Related: SA-4,SA-8,SC-3

Category: SYSTEM AND COMMUNICATIONS PROTECTION

Family: SYSTEM AND COMMUNICATIONS PROTECTION

Priority: P1

Baseline Impact: MODERATE,HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.5.4 Ensure kernel.dmesg_restrict is configuredUnixCIS SUSE Linux Enterprise 16 v1.0.0 L1 Server
1.5.4 Ensure kernel.dmesg_restrict is configuredUnixCIS SUSE Linux Enterprise 16 v1.0.0 L1 Workstation
1.5.5 Ensure kernel.dmesg_restrict is configuredUnixCIS Amazon Linux 2 v4.0.0 L1 Server
1.5.5 Ensure kernel.dmesg_restrict is configuredUnixCIS Debian Linux 13 v1.0.0 L1 Server
1.5.5 Ensure kernel.dmesg_restrict is configuredUnixCIS Rocky Linux 10 v1.0.0 L1 Server
1.5.5 Ensure kernel.dmesg_restrict is configuredUnixCIS Rocky Linux 10 v1.0.0 L1 Workstation
1.5.5 Ensure kernel.dmesg_restrict is configuredUnixCIS Debian Linux 13 v1.0.0 L1 Workstation
1.8 AZLX-23-000200UnixCIS Amazon Linux 2023 STIG v1.0.0 CAT II
1.9 AZLX-23-000205UnixCIS Amazon Linux 2023 STIG v1.0.0 CAT II
1.10 AZLX-23-000210UnixCIS Amazon Linux 2023 STIG v1.0.0 CAT II
1.11 AZLX-23-000215UnixCIS Amazon Linux 2023 STIG v1.0.0 CAT II
1.12 AZLX-23-000220UnixCIS Amazon Linux 2023 STIG v1.0.0 CAT II
1.16 EX19-ED-000094WindowsCIS Microsoft Exchange 2019 Edge Server STIG v1.0.0 CAT II
1.18 VCSA-80-000095VMwareCIS VMware vSphere 8.0 vCenter STIG v1.0.0 CAT II
1.21 RHEL-09-213010UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.22 RHEL-09-213015UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.24 RHEL-09-213025UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.25 EX19-MB-000105WindowsCIS Microsoft Exchange 2019 Mailbox Server STIG v1.0.0 CAT II
1.34 RHEL-09-213075UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.35 RHEL-09-213080UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.78 O19C-00-016100OracleDBCIS Oracle Database 19c STIG v1.1.0 CAT II OracleDB
1.308 OL09-00-002406UnixCIS Oracle Linux 9 STIG v1.0.0 CAT II
1.309 OL09-00-002407UnixCIS Oracle Linux 9 STIG v1.0.0 CAT II
1.310 OL09-00-002408UnixCIS Oracle Linux 9 STIG v1.0.0 CAT II
1.311 OL09-00-002409UnixCIS Oracle Linux 9 STIG v1.0.0 CAT II
1.312 OL09-00-002410UnixCIS Oracle Linux 9 STIG v1.0.0 CAT II
1.374 RHEL-10-701030UnixCIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT II
1.375 RHEL-10-701040UnixCIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT II
1.377 RHEL-10-701060UnixCIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT II
1.385 RHEL-10-701140UnixCIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT II
1.404 RHEL-10-800030UnixCIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT II
ALMA-09-040720 - AlmaLinux OS 9 must disable access to network bpf system call from nonprivileged processes.UnixDISA Cloud Linux AlmaLinux OS 9 STIG v1r6
ALMA-09-040830 - AlmaLinux OS 9 must restrict exposed kernel pointer addresses access.UnixDISA Cloud Linux AlmaLinux OS 9 STIG v1r6
ALMA-09-040940 - AlmaLinux OS 9 must restrict usage of ptrace to descendant processes.UnixDISA Cloud Linux AlmaLinux OS 9 STIG v1r6
ALMA-09-041050 - AlmaLinux OS 9 must restrict access to the kernel message buffer.UnixDISA Cloud Linux AlmaLinux OS 9 STIG v1r6
ALMA-09-041160 - AlmaLinux OS 9 must prevent kernel profiling by nonprivileged users.UnixDISA Cloud Linux AlmaLinux OS 9 STIG v1r6
AS24-U1-000430 - Apache web server accounts accessing the directory tree, the shell, or other operating system functions and utilities must only be administrative accounts.UnixDISA STIG Apache Server 2.4 Unix Server v3r2
AS24-U1-000430 - Apache web server accounts accessing the directory tree, the shell, or other operating system functions and utilities must only be administrative accounts.UnixDISA STIG Apache Server 2.4 Unix Server v3r2 Middleware
AS24-U1-000440 - Apache web server application directories, libraries, and configuration files must only be accessible to privileged users.UnixDISA STIG Apache Server 2.4 Unix Server v3r2
AS24-U1-000440 - Apache web server application directories, libraries, and configuration files must only be accessible to privileged users.UnixDISA STIG Apache Server 2.4 Unix Server v3r2 Middleware
AS24-U1-000450 - The Apache web server must separate the hosted applications from hosted Apache web server management functionality.UnixDISA STIG Apache Server 2.4 Unix Server v3r2
AS24-U1-000450 - The Apache web server must separate the hosted applications from hosted Apache web server management functionality.UnixDISA STIG Apache Server 2.4 Unix Server v3r2 Middleware
AS24-W1-000280 - Apache web server application directories, libraries, and configuration files must only be accessible to privileged users.WindowsDISA STIG Apache Server 2.4 Windows Server v2r3
AS24-W1-000280 - Apache web server application directories, libraries, and configuration files must only be accessible to privileged users.WindowsDISA STIG Apache Server 2.4 Windows Server v3r4
AS24-W1-000430 - Apache web server accounts accessing the directory tree, the shell, or other operating system functions and utilities must only be administrative accounts.WindowsDISA STIG Apache Server 2.4 Windows Server v2r3
AS24-W1-000430 - Apache web server accounts accessing the directory tree, the shell, or other operating system functions and utilities must only be administrative accounts.WindowsDISA STIG Apache Server 2.4 Windows Server v3r4
AS24-W1-000450 - The Apache web server must separate the hosted applications from hosted Apache web server management functionality.WindowsDISA STIG Apache Server 2.4 Windows Server v2r3
AS24-W1-000450 - The Apache web server must separate the hosted applications from hosted Apache web server management functionality.WindowsDISA STIG Apache Server 2.4 Windows Server v3r4
AS24-W2-000430 - Apache web server accounts accessing the directory tree, the shell, or other operating system functions and utilities must only be administrative accounts.WindowsDISA Apache Server 2.4 Windows Site STIG v2r3
AS24-W2-000440 - Anonymous user access to the Apache web server application directories must be prohibited.WindowsDISA Apache Server 2.4 Windows Site STIG v2r3