SC-4 Information in Shared System Resources
System and Communications Protection family. 3 Control Correlation Identifiers map to this control, and 28 STIG rules implement those CCIs.
The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.
It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.
Where these rules come from
| STIG benchmark | Version | Rules mapped to SC-4 |
|---|---|---|
| Microsoft Windows 10 | V3 | 6 |
| Microsoft Windows Server 2019 | V3 | 5 |
| Microsoft Windows 11 | V2 | 5 |
| Microsoft Windows Server 2022 | V2 | 5 |
| Red Hat Enterprise Linux 9 | V2 | 4 |
| Red Hat Enterprise Linux 8 | V2 | 3 |
Control Correlation Identifiers mapped to SC-4
| CCI | Definition | Rev |
|---|---|---|
| CCI-001090 | Prevent unauthorized and unintended information transfer via shared system resources. | 5, 4 |
| CCI-002383 | Defines the procedures to be employed to prevent unauthorized information transfer via shared resources when system processing explicitly switches between different information classification levels or security categories. | 5, 4 |
| CCI-002384 | Prevent unauthorized information transfer via shared resources in accordance with organization-defined procedures when system processing explicitly switches between different information classification levels or security categories. | 5, 4 |
STIG rules that implement SC-4
| Rule | STIG ID | Severity | Requirement |
|---|---|---|---|
| V-205721 | WN19-00-000230 | medium | Windows Server 2019 non-system-created file shares must limit access to groups that require it. |
| V-205722 | WN19-CC-000350 | medium | Windows Server 2019 Remote Desktop Services must prevent drive redirection. |
| V-205723 | WN19-DC-000120 | medium | Windows Server 2019 data files owned by users must be on a different logical partition from the directory server data files. |
| V-205724 | WN19-SO-000230 | high | Windows Server 2019 must not allow anonymous enumeration of shares. |
| V-205725 | WN19-SO-000250 | high | Windows Server 2019 must restrict anonymous access to Named Pipes and Shares. |
| V-220710 | WN10-00-000060 | medium | Non system-created file shares on a system must limit access to groups that require it. |
| V-220823 | WN10-CC-000155 | high | Solicited Remote Assistance must not be allowed. |
| V-220849 | WN10-CC-000275 | medium | Local drives must be prevented from sharing with Remote Desktop Session Hosts. |
| V-220902 | WN10-EP-000310 | medium | Windows 10 Kernel (Direct Memory Access) DMA Protection must be enabled. |
| V-220930 | WN10-SO-000150 | high | Anonymous enumeration of shares must be restricted. |
| V-220932 | WN10-SO-000165 | high | Anonymous access to Named Pipes and Shares must be restricted. |
| V-230243 | RHEL-08-010190 | medium | A sticky bit must be set on all RHEL 8 public directories to prevent unauthorized and unintended information transferred via shared system resources. |
| V-230269 | RHEL-08-010375 | low | RHEL 8 must restrict access to the kernel message buffer. |
| V-230270 | RHEL-08-010376 | low | RHEL 8 must prevent kernel profiling by unprivileged users. |
| V-253267 | WN11-00-000060 | medium | Non-system-created file shares on a system must limit access to groups that require it. |
| V-253382 | WN11-CC-000155 | high | Solicited Remote Assistance must not be allowed. |
| V-253403 | WN11-CC-000275 | medium | Local drives must be prevented from sharing with Remote Desktop Session Hosts. |
| V-253454 | WN11-SO-000150 | high | Anonymous enumeration of shares must be restricted. |
| V-253456 | WN11-SO-000165 | high | Anonymous access to Named Pipes and Shares must be restricted. |
| V-254260 | WN22-00-000230 | medium | Windows Server 2022 nonsystem-created file shares must limit access to groups that require it. |
| V-254366 | WN22-CC-000350 | medium | Windows Server 2022 Remote Desktop Services must prevent drive redirection. |
| V-254396 | WN22-DC-000120 | medium | Windows Server 2022 data files owned by users must be on a different logical partition from the directory server data files. |
| V-254467 | WN22-SO-000230 | high | Windows Server 2022 must not allow anonymous enumeration of shares. |
| V-254469 | WN22-SO-000250 | high | Windows Server 2022 must restrict anonymous access to Named Pipes and Shares. |
| V-257797 | RHEL-09-213010 | medium | RHEL 9 must restrict access to the kernel message buffer. |
| V-257798 | RHEL-09-213015 | medium | RHEL 9 must prevent kernel profiling by nonprivileged users. |
| V-257928 | RHEL-09-232240 | medium | All RHEL 9 world-writable directories must be owned by root, sys, bin, or an application user. |
| V-257929 | RHEL-09-232245 | medium | A sticky bit must be set on all RHEL 9 public directories. |
Get this as data
The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/SC-4. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.