← Controls / SC

SC-02 Separation of System and User Functionality

System and Communications Protection

Moderate High

Description

Separate user functionality, including user interface services, from system management functionality.

Supplemental Guidance

System management functionality includes functions that are necessary to administer databases, network components, workstations, or servers. These functions typically require privileged user access. The separation of user functions from system management functions is physical or logical. Organizations may separate system management functions from user functions by using different computers, instances of operating systems, central processing units, or network addresses; by employing virtualization techniques; or some combination of these or other methods. Separation of system management functions from user functions includes web administrative interfaces that employ separate authentication methods for users of any other system resources. Separation of system and user functions may include isolating administrative interfaces on different domains and with additional access controls. The separation of system and user functionality can be achieved by applying the systems security engineering design principles in SA-08, including SA-08(01), SA-08(03), SA-08(04), SA-08(10), SA-08(12), SA-08(13), SA-08(14), and SA-08(18).

Enhancements (2)

What NIST adds to this control. Select one to read its statement.

SC-02(01) Interfaces for Non-privileged Users

Prevent the presentation of system management functionality at interfaces to non-privileged users.

SC-02(02) Disassociability

Store state information from applications and software separately.

Patterns that use this control (2)

Grouped by the emphasis each pattern gives it.

MITRE ATT&CK Techniques (8)

ATT&CK v16.1

Techniques mitigated by this control, mapped via CTID.

Initial Access 2 Execution 1 Privilege Escalation 2 Defense Evasion 1 Credential Access 1 Lateral Movement 1

Compliance Mappings

ANSSI

Hygiene.23SecNumCloud.14.1

FINMA Circular 2023/1

IV.C(62)IV.C(63)

OSFI B-13

B-13.2.2B-13.3.2

EU GDPR

Art.5(1)(f)Art.32(1)(b)

EU DORA

Art.9(4)(a)

RBI CSF

Annex1.6

FISC Security Guidelines

FISC.T3FISC.T14

HKMA TM-E-1

TME1.7.3

NCA ECC

2-3

CBB TM

TM-8

Qatar NIA

CS

BoG CISD

CISD-VI

IOSCO Cyber Resilience

PROT-2

BCBS 239

Principle 2

CPMI-IOSCO PFMI

CG.PR

FFIEC IS

II.C.2II.C.15(b)

HIPAA Security Rule

§164.308(a)(4)(ii)(A)

ECB CROE

CROE.2.3.5

BOT Cyber Resilience

Ch2.4

CMMC 2.0

SC

FERC CIP Orders

Order 887

Solvency II

EIOPA-ICT-4.6

PRA SS1/23

P-IT.3

Basel SCO60

SCO60.64

SEC Custody (Digital Assets)

SEC-CD-04

ISO 17799 (legacy)

11.4.5

COBIT 4.1 (legacy)

AI2.4