Show/Hide Toolbars

ABCI Consultants

Guidance for NIST 800-171 Assessment & Compliance

Navigation: SC-FAMILY: SYSTEM AND COMMUNICATIONS PROTECTION

SC-7(13) BOUNDARY PROTECTION  |  ISOLATION OF SECURITY TOOLS / MECHANISMS / SUPPORT COMPONENTS

Scroll Prev Top Next More

Applicable

(Y)es / (N)o

(C)onfidentiality

(I)ntegrity

(A)vailability

RPN

(C+I+A)

(S)atisfactory

L1

M2

H3

L1

M2

H3

L1

M2

H3

(O)ther than satisfactory +##

 

 

 

 

 

 

 

 

 

 

 

 

###

sc-7(13)

boundary protection  | isolation of security tools / mechanisms / support components

 

assessment objective:

Determine if the organization:

sc-7(13)[1]

defines information security tools, mechanisms, and support components to be isolated from other internal information system components; and

sc-7(13)[2]

isolates organization-defined information security tools, mechanisms, and support components from other internal information system components by implementing physically separate subnetworks with managed interfaces to other components of the system.

potential assessment methods and objects:

Examine: [select from: System and communications protection policy; procedures addressing boundary protection; information system design documentation; information system hardware and software; information system architecture; information system configuration settings and associated documentation; list of security tools and support components to be isolated from other internal information system components; information system audit records; other relevant documents or records].

Interview: [select from: System/network administrators; organizational personnel with information security responsibilities; organizational personnel with boundary protection responsibilities].

Test: [select from: Automated mechanisms supporting and/or implementing isolation of information security tools, mechanisms, and support components].

Hosted by ABCI Consultants for Information Security Management Systems | Implementations, Training and Assessments for Compliance | (800) 644-2056