PlumbTrackLive demoGRC Risk System

← control library

Separation of System and User Functionality SC-2

System and Communications Protection · Moderate baseline ✗ Not implemented

Status — program-wide

What references this control

No risks name this control in their Framework field yet.

No policies reference it yet.


Link a risk or policy to this control

Attaching adds SC-2 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.

Source: NIST SP 800-53 Rev.5, System and Communications Protection family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.

Control guide — plain-English, per NIST SP 800-53

SC-2 (Separation of System and User Functionality) says keep the administrative side of a system apart from the everyday user side. The tools and interfaces used to manage the machine — the privileged, system-management functions — should be separated, physically or logically, from the interfaces that ordinary users touch, so that simply using the system does not hand someone the controls to run it. It is an SC (System and Communications Protection) control in the Moderate baseline.

What good looks like

Framework mapping

How to move it toward Implemented