San Antonio, TX · Military City, USA UEI L58JZMKRCLM5  ·  CAGE 203C1  ·  NAICS 541511  ·  SAM.gov Active

SC-3 Security Function Isolation

System and Communications Protection family. 6 Control Correlation Identifiers map to this control, and 37 STIG rules implement those CCIs.

2CAT I (high)
34CAT II (medium)
1CAT III (low)
6CCIs
What this page is built from, and what it is not.

The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.

It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.

Where these rules come from

STIG benchmarkVersionRules mapped to SC-3
Microsoft Windows Server 2019V37
Microsoft Windows Server 2022V27
Microsoft Windows 10V36
Microsoft Windows 11V26
Red Hat Enterprise Linux 8V25
Red Hat Enterprise Linux 9V25
KubernetesV21

Control Correlation Identifiers mapped to SC-3

CCIDefinitionRev
CCI-001084Isolate security functions from nonsecurity functions.5, 4
CCI-001085Employ hardware separation mechanisms to implement security function isolation.5, 4
CCI-001086Isolate security functions enforcing access and information flow control from both nonsecurity functions and from other security functions.5, 4
CCI-001089Implement security functions as a layered structure minimizing interactions between layers of the design and avoiding any dependence by lower layers on the functionality or correctness of higher layers.5, 4
CCI-002381Minimize the number of nonsecurity functions included within the isolation boundary containing security functions.5, 4
CCI-002382Implement security functions as largely independent modules that maximize internal cohesiveness within modules and minimize coupling between modules.5, 4

STIG rules that implement SC-3

RuleSTIG IDSeverityRequirement
V-205714WN19-CC-000240mediumWindows Server 2019 administrator accounts must not be enumerated during elevation.
V-205715WN19-MS-000020mediumWindows Server 2019 local administrator accounts must have their privileged token filtered to prevent elevated privileges from being used over the network on domain-joined member servers.
V-205716WN19-SO-000390mediumWindows Server 2019 UIAccess applications must not be allowed to prompt for elevation without using the secure desktop.
V-205717WN19-SO-000400mediumWindows Server 2019 User Account Control must, at a minimum, prompt administrators for consent on the secure desktop.
V-205718WN19-SO-000420mediumWindows Server 2019 User Account Control must be configured to detect application installations and prompt for elevation.
V-205719WN19-SO-000430mediumWindows Server 2019 User Account Control (UAC) must only elevate UIAccess applications that are installed in secure locations.
V-205720WN19-SO-000450mediumWindows Server 2019 User Account Control (UAC) must virtualize file and registry write failures to per-user locations.
V-220799WN10-CC-000037mediumLocal administrator accounts must have their privileged token filtered to prevent elevated privileges from being used over the network on domain systems.
V-220832WN10-CC-000200mediumAdministrator accounts must not be enumerated during elevation.
V-220945WN10-SO-000250mediumUser Account Control must, at minimum, prompt administrators for consent on the secure desktop.
V-220948WN10-SO-000260mediumUser Account Control must be configured to detect application installations and prompt for elevation.
V-220949WN10-SO-000265mediumUser Account Control must only elevate UIAccess applications that are installed in secure locations.
V-220951WN10-SO-000275mediumUser Account Control must virtualize file and registry write failures to per-user locations.
V-230240RHEL-08-010170mediumRHEL 8 must use a Linux Security Module configured to enforce limits on system services.
V-230241RHEL-08-010171lowRHEL 8 must have policycoreutils package installed.
V-230277RHEL-08-010421mediumRHEL 8 must clear the page allocator to prevent use-after-free attacks.
V-230278RHEL-08-010422mediumRHEL 8 must disable virtual syscalls.
V-230279RHEL-08-010423mediumRHEL 8 must clear memory when it is freed to prevent use-after-free attacks.
V-242434CNTR-K8-001620highKubernetes Kubelet must enable kernel protection.
V-253357WN11-CC-000037mediumLocal administrator accounts must have their privileged token filtered to prevent elevated privileges from being used over the network on domain systems.
V-253391WN11-CC-000200mediumAdministrator accounts must not be enumerated during elevation.
V-253469WN11-SO-000250mediumUser Account Control must prompt administrators for consent on the secure desktop.
V-253472WN11-SO-000260mediumUser Account Control must be configured to detect application installations and prompt for elevation.
V-253473WN11-SO-000265mediumUser Account Control must only elevate UIAccess applications that are installed in secure locations.
V-253475WN11-SO-000275mediumUser Account Control must virtualize file and registry write failures to per-user locations.
V-254355WN22-CC-000240mediumWindows Server 2022 administrator accounts must not be enumerated during elevation.
V-254429WN22-MS-000020mediumWindows Server 2022 local administrator accounts must have their privileged token filtered to prevent elevated privileges from being used over the network on domain-joined member servers.
V-254483WN22-SO-000390mediumWindows Server 2022 UIAccess applications must not be allowed to prompt for elevation without using the secure desktop.
V-254484WN22-SO-000400mediumWindows Server 2022 User Account Control (UAC) must, at a minimum, prompt administrators for consent on the secure desktop.
V-254486WN22-SO-000420mediumWindows Server 2022 User Account Control (UAC) must be configured to detect application installations and prompt for elevation.
V-254487WN22-SO-000430mediumWindows Server 2022 User Account Control (UAC) must only elevate UIAccess applications that are installed in secure locations.
V-254489WN22-SO-000450mediumWindows Server 2022 User Account Control (UAC) must virtualize file and registry write failures to per-user locations.
V-257792RHEL-09-212035mediumRHEL 9 must disable virtual system calls.
V-257793RHEL-09-212040mediumRHEL 9 must clear the page allocator to prevent use-after-free attacks.
V-257794RHEL-09-212045mediumRHEL 9 must clear memory when it is freed to prevent use-after-free attacks.
V-258078RHEL-09-431010highRHEL 9 must use a Linux Security Module configured to enforce limits on system services.
V-258081RHEL-09-431025mediumRHEL 9 must have policycoreutils package installed.

Get this as data

The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/SC-3. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.