03.13.04: Information in Shared System Resources
Control Familly: System and Communications Protection
SPRS: N/A
Top Ten Failed Requirement: N/A
Supporting Publications:
N/A
Referenced in: N/A
Control Type: N/A
CPCSC Level 2: 03.13.04
CMMC Level(s): N/A
Derived From: NIST SP 800-53r5
SC-04
Prevent unauthorized and unintended information transfer via shared system resources.
Discussion:
Preventing unauthorized and unintended information transfer via shared system resources stops information produced by the actions of prior users or roles (or actions of processes acting on behalf of prior users or roles) from being available to current users or roles (or current processes acting on behalf of current users or roles) that obtain access to shared system resources after those resources have been released back to the system. Information in shared system resources also applies to encrypted representations of information. In other contexts, the control of information in shared system resources is referred to as object reuse and residual information protection. Information in shared system resources does not address information remanence, which refers to the residual representation of data that has been nominally deleted, covert channels (including storage and timing channels) in which shared system resources are manipulated to violate information flow restrictions, or components within systems for which there are only single users or roles.
Assessment Methods and Objectives
Examine [SELECT FROM: system and communications protection policy and procedures; procedures for information protection in shared system resources; system configuration settings; system audit records; system design documentation; system security plan; other relevant documents or records]
Interview [SELECT FROM: personnel with information security responsibilities; system developers; system administrators]
Test [SELECT FROM: mechanisms for preventing the unauthorized and unintended transfer of information via shared system resources]
NIST SP 800-171A r3 Determining Statements Determine if:
A.03.13.04[01]: unauthorized information transfer via shared system resources is prevented.
A.03.13.04[02]: unintended information transfer via shared system resources is prevented.
The Security Requirements
NIST SP 800-171r3 (USA) & ITSP.10.171 (Canada)
3.5. Identification and Authentication
3.12. Security Assessment and Monitoring
3.13. System and Communications Protection
3.14. System and Information Integrity
3.16. System and Services Acquisition
3.17. Supply Chain Risk Management
CMMC 3.0 - N/A
CPCSC - N/A