SC-3 Security Function Isolation
System and Communications Protection family. 6 Control Correlation Identifiers map to this control, and 37 STIG rules implement those CCIs.
The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.
It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.
Where these rules come from
| STIG benchmark | Version | Rules mapped to SC-3 |
|---|---|---|
| Microsoft Windows Server 2019 | V3 | 7 |
| Microsoft Windows Server 2022 | V2 | 7 |
| Microsoft Windows 10 | V3 | 6 |
| Microsoft Windows 11 | V2 | 6 |
| Red Hat Enterprise Linux 8 | V2 | 5 |
| Red Hat Enterprise Linux 9 | V2 | 5 |
| Kubernetes | V2 | 1 |
Control Correlation Identifiers mapped to SC-3
| CCI | Definition | Rev |
|---|---|---|
| CCI-001084 | Isolate security functions from nonsecurity functions. | 5, 4 |
| CCI-001085 | Employ hardware separation mechanisms to implement security function isolation. | 5, 4 |
| CCI-001086 | Isolate security functions enforcing access and information flow control from both nonsecurity functions and from other security functions. | 5, 4 |
| CCI-001089 | Implement security functions as a layered structure minimizing interactions between layers of the design and avoiding any dependence by lower layers on the functionality or correctness of higher layers. | 5, 4 |
| CCI-002381 | Minimize the number of nonsecurity functions included within the isolation boundary containing security functions. | 5, 4 |
| CCI-002382 | Implement security functions as largely independent modules that maximize internal cohesiveness within modules and minimize coupling between modules. | 5, 4 |
STIG rules that implement SC-3
| Rule | STIG ID | Severity | Requirement |
|---|---|---|---|
| V-205714 | WN19-CC-000240 | medium | Windows Server 2019 administrator accounts must not be enumerated during elevation. |
| V-205715 | WN19-MS-000020 | medium | Windows Server 2019 local administrator accounts must have their privileged token filtered to prevent elevated privileges from being used over the network on domain-joined member servers. |
| V-205716 | WN19-SO-000390 | medium | Windows Server 2019 UIAccess applications must not be allowed to prompt for elevation without using the secure desktop. |
| V-205717 | WN19-SO-000400 | medium | Windows Server 2019 User Account Control must, at a minimum, prompt administrators for consent on the secure desktop. |
| V-205718 | WN19-SO-000420 | medium | Windows Server 2019 User Account Control must be configured to detect application installations and prompt for elevation. |
| V-205719 | WN19-SO-000430 | medium | Windows Server 2019 User Account Control (UAC) must only elevate UIAccess applications that are installed in secure locations. |
| V-205720 | WN19-SO-000450 | medium | Windows Server 2019 User Account Control (UAC) must virtualize file and registry write failures to per-user locations. |
| V-220799 | WN10-CC-000037 | medium | Local administrator accounts must have their privileged token filtered to prevent elevated privileges from being used over the network on domain systems. |
| V-220832 | WN10-CC-000200 | medium | Administrator accounts must not be enumerated during elevation. |
| V-220945 | WN10-SO-000250 | medium | User Account Control must, at minimum, prompt administrators for consent on the secure desktop. |
| V-220948 | WN10-SO-000260 | medium | User Account Control must be configured to detect application installations and prompt for elevation. |
| V-220949 | WN10-SO-000265 | medium | User Account Control must only elevate UIAccess applications that are installed in secure locations. |
| V-220951 | WN10-SO-000275 | medium | User Account Control must virtualize file and registry write failures to per-user locations. |
| V-230240 | RHEL-08-010170 | medium | RHEL 8 must use a Linux Security Module configured to enforce limits on system services. |
| V-230241 | RHEL-08-010171 | low | RHEL 8 must have policycoreutils package installed. |
| V-230277 | RHEL-08-010421 | medium | RHEL 8 must clear the page allocator to prevent use-after-free attacks. |
| V-230278 | RHEL-08-010422 | medium | RHEL 8 must disable virtual syscalls. |
| V-230279 | RHEL-08-010423 | medium | RHEL 8 must clear memory when it is freed to prevent use-after-free attacks. |
| V-242434 | CNTR-K8-001620 | high | Kubernetes Kubelet must enable kernel protection. |
| V-253357 | WN11-CC-000037 | medium | Local administrator accounts must have their privileged token filtered to prevent elevated privileges from being used over the network on domain systems. |
| V-253391 | WN11-CC-000200 | medium | Administrator accounts must not be enumerated during elevation. |
| V-253469 | WN11-SO-000250 | medium | User Account Control must prompt administrators for consent on the secure desktop. |
| V-253472 | WN11-SO-000260 | medium | User Account Control must be configured to detect application installations and prompt for elevation. |
| V-253473 | WN11-SO-000265 | medium | User Account Control must only elevate UIAccess applications that are installed in secure locations. |
| V-253475 | WN11-SO-000275 | medium | User Account Control must virtualize file and registry write failures to per-user locations. |
| V-254355 | WN22-CC-000240 | medium | Windows Server 2022 administrator accounts must not be enumerated during elevation. |
| V-254429 | WN22-MS-000020 | medium | Windows Server 2022 local administrator accounts must have their privileged token filtered to prevent elevated privileges from being used over the network on domain-joined member servers. |
| V-254483 | WN22-SO-000390 | medium | Windows Server 2022 UIAccess applications must not be allowed to prompt for elevation without using the secure desktop. |
| V-254484 | WN22-SO-000400 | medium | Windows Server 2022 User Account Control (UAC) must, at a minimum, prompt administrators for consent on the secure desktop. |
| V-254486 | WN22-SO-000420 | medium | Windows Server 2022 User Account Control (UAC) must be configured to detect application installations and prompt for elevation. |
| V-254487 | WN22-SO-000430 | medium | Windows Server 2022 User Account Control (UAC) must only elevate UIAccess applications that are installed in secure locations. |
| V-254489 | WN22-SO-000450 | medium | Windows Server 2022 User Account Control (UAC) must virtualize file and registry write failures to per-user locations. |
| V-257792 | RHEL-09-212035 | medium | RHEL 9 must disable virtual system calls. |
| V-257793 | RHEL-09-212040 | medium | RHEL 9 must clear the page allocator to prevent use-after-free attacks. |
| V-257794 | RHEL-09-212045 | medium | RHEL 9 must clear memory when it is freed to prevent use-after-free attacks. |
| V-258078 | RHEL-09-431010 | high | RHEL 9 must use a Linux Security Module configured to enforce limits on system services. |
| V-258081 | RHEL-09-431025 | medium | RHEL 9 must have policycoreutils package installed. |
Get this as data
The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/SC-3. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.