Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family SC

SC-3Security Function Isolation

Isolate security functions from nonsecurity functions.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (18)

Weaknesses this control addresses (6)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-284Improper Access Control4,832By design the control implements a hard boundary that prevents unauthorized actors or non-security functions from reaching security-critical resources or entry points.
CWE-269Improper Privilege Management2,907The control enforces separation so that privilege management decisions and operations for security functions cannot be influenced or subverted by non-security code.
CWE-732Incorrect Permission Assignment for Critical Resource1,824Security functions become critical resources whose permissions can be assigned narrowly and independently of the rest of the system.
CWE-250Execution with Unnecessary Privileges305Isolating security functions allows them to execute with only the privileges they require while preventing non-security code from inheriting or accessing those privileges.
CWE-1220Insufficient Granularity of Access Control79Isolation supplies an explicit, enforceable granularity boundary between security and non-security functions that coarser access-control schemes lack.
CWE-653Improper Isolation or Compartmentalization52The control directly supplies the compartmentalization that CWE-653 requires between security and non-security domains.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2024-299702.09.80.0028partial

Other controls in family SC

SC-1 SC-10 SC-11 SC-12 SC-13 SC-14 SC-15 SC-16 SC-17 SC-18 SC-19 SC-2 SC-20 SC-21 SC-22 SC-23 SC-24 SC-25 SC-26 SC-27 SC-28 SC-29 SC-30 SC-31 SC-32 SC-33 SC-34 SC-35 SC-36 SC-37 SC-38 SC-39 SC-4 SC-40 SC-41 SC-42 SC-43 SC-44 SC-45 SC-46 SC-47 SC-48 SC-49 SC-5 SC-50 SC-51 SC-6 SC-7 SC-8 SC-9