PlumbTrackLive demoGRC Risk System

← internal audit

Audit — SC-3 — Security Function Isolation

Framework: NIST SP 800-53 Rev.5 SC-3 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 6 checked
Examine Review architecture documentation to confirm security functions (access control, auditing, cryptography, boundary protection) are isolated from non-security/user functions via separate execution domains, hosts, VLANs, or privilege rings.
Interview Ask architects/engineers how the boundary between security-relevant and non-security components is defined, and how that isolation is enforced and maintained through changes.
Test Verify that non-privileged user-level processes cannot read or modify security-function code, configuration, or memory (attempt access and confirm it is denied).
Examine Confirm security management interfaces (admin consoles, jump/bastion hosts) reside on a separate management plane/network isolated from general user and application traffic.
Examine Review hardening/configuration baselines to confirm security services run with least privilege and are segregated from application workloads (dedicated accounts, containers, or hosts).
Interview Confirm separation of duties between staff who administer security functions and those who administer general system/application functions is defined and enforced.