SC-39-727 Process Isolation

Process Isolation

SC-39-727
Process Isolation
System and Communications Protection
Protect
System Communications Protection
LOW, MOD, HIGH
P1
Yes
Insufficient segregation of communications and interfaces between the system processes, may expose sensitive information resources to unauthorized access.
The information system maintains a separate execution domain for each executing process.
The information system automatically enables a separate execution domain.
The organization uses operating systems that support process isolation.
Obtain procedures addressing process isolation and ascertain if: (i) Information systems maintain separate execution domains for each executing process (ii) Each information system process has a distinct address space to securely control the communications and interfaces between the two processes (such that one process cannot modify the executing code of another process)