PlumbTrackLive demoGRC Risk System

← control library

Security Function Isolation SC-3

System and Communications Protection · High baseline ✗ Not implemented

Status — program-wide

What references this control

No risks name this control in their Framework field yet.

No policies reference it yet.


Link a risk or policy to this control

Attaching adds SC-3 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.

Source: NIST SP 800-53 Rev.5, System and Communications Protection family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.

Control guide — plain-English, per NIST SP 800-53

SC-3 (Security Function Isolation) goes a step beyond SC-2. It asks that the parts of the system that enforce security — the access-control checks, the security-relevant code, and its configuration — be kept isolated from the ordinary, non-security parts, so that a bug or compromise in general software cannot reach in and tamper with the security machinery. It is an SC (System and Communications Protection) control in the High baseline, usually met by the operating system’s own design plus the boundaries you keep intact.

What good looks like

Framework mapping

How to move it toward Implemented