| name | SC-46_cross-domain-policy-enforcement |
| description | Implement a policy enforcement mechanism [organization-defined] between the physical and/or network interfaces for the connecting security domains. |
| category | configuration |
| version | 5.2.0 |
| author | cyberstrike-official |
| tags | ["nist","sp800-53","rev5","sc-46","sc"] |
| tech_stack | ["aws","azure","gcp","linux","windows","network"] |
| cwe_ids | ["CWE-311"] |
| chains_with | ["AC-4","SC-7"] |
| prerequisites | [] |
| severity_boost | {"AC-4":"Chain with AC-4 for comprehensive security coverage","SC-7":"Chain with SC-7 for comprehensive security coverage"} |
SC-46 Cross Domain Policy Enforcement
High-Level Description
Family: System and Communications Protection (SC)
Framework: NIST SP 800-53 Rev 5
For logical policy enforcement mechanisms, organizations avoid creating a logical path between interfaces to prevent the ability to bypass the policy enforcement mechanism. For physical policy enforcement mechanisms, the robustness of physical isolation afforded by the physical implementation of policy enforcement to preclude the presence of logical covert channels penetrating the security domain may be needed. Contact ncdsmo@nsa.gov for more information.
What to Check
How to Test
Step 1: Review Documentation
Examine the System Security Plan (SSP) and related artifacts for SC-46 implementation details. Verify the organization has documented how this control is satisfied.
Step 2: Validate Implementation
# For cloud environments, use cloud-audit-mcp tools
# For on-premises, review system configurations directly
# Example: Check if account management policies exist
grep -r "account.management\|access.control" /etc/security/ 2>/dev/null
Step 3: Test Operating Effectiveness
Verify the control is actively functioning, not just documented. Check logs, configurations, and operational evidence.
Tools
| Tool | Purpose | Usage |
|---|
| cloud-audit-mcp | Check encryption and network controls | cloud_audit_encryption |
| nmap | Network scanning | nmap -sV --script ssl-enum-ciphers |
Remediation Guide
Control Statement
Implement a policy enforcement mechanism [organization-defined] between the physical and/or network interfaces for the connecting security domains.
Implementation Guidance
For logical policy enforcement mechanisms, organizations avoid creating a logical path between interfaces to prevent the ability to bypass the policy enforcement mechanism. For physical policy enforcement mechanisms, the robustness of physical isolation afforded by the physical implementation of policy enforcement to preclude the presence of logical covert channels penetrating the security domain may be needed. Contact for more information.