San Antonio, TX · Military City, USA UEI L58JZMKRCLM5  ·  CAGE 203C1  ·  NAICS 541511  ·  SAM.gov Active

SC-4 Information in Shared System Resources

System and Communications Protection family. 3 Control Correlation Identifiers map to this control, and 28 STIG rules implement those CCIs.

10CAT I (high)
16CAT II (medium)
2CAT III (low)
3CCIs
What this page is built from, and what it is not.

The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.

It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.

Where these rules come from

STIG benchmarkVersionRules mapped to SC-4
Microsoft Windows 10V36
Microsoft Windows Server 2019V35
Microsoft Windows 11V25
Microsoft Windows Server 2022V25
Red Hat Enterprise Linux 9V24
Red Hat Enterprise Linux 8V23

Control Correlation Identifiers mapped to SC-4

CCIDefinitionRev
CCI-001090Prevent unauthorized and unintended information transfer via shared system resources.5, 4
CCI-002383Defines the procedures to be employed to prevent unauthorized information transfer via shared resources when system processing explicitly switches between different information classification levels or security categories.5, 4
CCI-002384Prevent unauthorized information transfer via shared resources in accordance with organization-defined procedures when system processing explicitly switches between different information classification levels or security categories.5, 4

STIG rules that implement SC-4

RuleSTIG IDSeverityRequirement
V-205721WN19-00-000230mediumWindows Server 2019 non-system-created file shares must limit access to groups that require it.
V-205722WN19-CC-000350mediumWindows Server 2019 Remote Desktop Services must prevent drive redirection.
V-205723WN19-DC-000120mediumWindows Server 2019 data files owned by users must be on a different logical partition from the directory server data files.
V-205724WN19-SO-000230highWindows Server 2019 must not allow anonymous enumeration of shares.
V-205725WN19-SO-000250highWindows Server 2019 must restrict anonymous access to Named Pipes and Shares.
V-220710WN10-00-000060mediumNon system-created file shares on a system must limit access to groups that require it.
V-220823WN10-CC-000155highSolicited Remote Assistance must not be allowed.
V-220849WN10-CC-000275mediumLocal drives must be prevented from sharing with Remote Desktop Session Hosts.
V-220902WN10-EP-000310mediumWindows 10 Kernel (Direct Memory Access) DMA Protection must be enabled.
V-220930WN10-SO-000150highAnonymous enumeration of shares must be restricted.
V-220932WN10-SO-000165highAnonymous access to Named Pipes and Shares must be restricted.
V-230243RHEL-08-010190mediumA sticky bit must be set on all RHEL 8 public directories to prevent unauthorized and unintended information transferred via shared system resources.
V-230269RHEL-08-010375lowRHEL 8 must restrict access to the kernel message buffer.
V-230270RHEL-08-010376lowRHEL 8 must prevent kernel profiling by unprivileged users.
V-253267WN11-00-000060mediumNon-system-created file shares on a system must limit access to groups that require it.
V-253382WN11-CC-000155highSolicited Remote Assistance must not be allowed.
V-253403WN11-CC-000275mediumLocal drives must be prevented from sharing with Remote Desktop Session Hosts.
V-253454WN11-SO-000150highAnonymous enumeration of shares must be restricted.
V-253456WN11-SO-000165highAnonymous access to Named Pipes and Shares must be restricted.
V-254260WN22-00-000230mediumWindows Server 2022 nonsystem-created file shares must limit access to groups that require it.
V-254366WN22-CC-000350mediumWindows Server 2022 Remote Desktop Services must prevent drive redirection.
V-254396WN22-DC-000120mediumWindows Server 2022 data files owned by users must be on a different logical partition from the directory server data files.
V-254467WN22-SO-000230highWindows Server 2022 must not allow anonymous enumeration of shares.
V-254469WN22-SO-000250highWindows Server 2022 must restrict anonymous access to Named Pipes and Shares.
V-257797RHEL-09-213010mediumRHEL 9 must restrict access to the kernel message buffer.
V-257798RHEL-09-213015mediumRHEL 9 must prevent kernel profiling by nonprivileged users.
V-257928RHEL-09-232240mediumAll RHEL 9 world-writable directories must be owned by root, sys, bin, or an application user.
V-257929RHEL-09-232245mediumA sticky bit must be set on all RHEL 9 public directories.

Get this as data

The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/SC-4. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.