Cyber Resilience

NIST 800-53 r5 · Controls catalogue · Family SC

SC-2Separation of System and User Functionality

Separate user functionality, including user interface services, from system management functionality.

Last updated: 22 August 2026 07:11 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (8)

Weaknesses this control addresses (7)AI-assisted

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-284Improper Access Control6,900+Explicit separation implements access control boundaries between user interfaces and system management functionality.
CWE-269Improper Privilege Management3,400+The control enforces proper privilege boundaries by ensuring user functionality cannot invoke or manage system-level privileges.
CWE-732Incorrect Permission Assignment for Critical Resource1,900+Ensures critical system resources and functions receive permission assignments distinct from ordinary user resources.
CWE-668Exposure of Resource to Wrong Sphere800+Prevents exposure of system management resources and functions into the user functionality sphere.
CWE-250Execution with Unnecessary Privileges300+Separating user-facing code from system management functions directly prevents execution of privileged operations from untrusted user contexts.
CWE-1220Insufficient Granularity of Access Control100+Provides the necessary granularity by placing system management functions outside the reach of user-level access controls.
CWE-653Improper Isolation or Compartmentalization73Directly requires isolation/compartmentalization of user services from system management functions.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2026-20271 6.18.60.0027partial
CVE-2025-22893 5.37.80.0013partial
CVE-2025-25273 5.37.80.0013partial
CVE-2025-35963 5.27.40.0019partial
CVE-2024-29079 5.16.80.0020partial
CVE-2025-25774 5.16.50.0041partial
CVE-2025-49463 5.16.50.0043partial
CVE-2021-33157 5.07.20.0020partial
CVE-2024-21801 5.07.10.0018partial
CVE-2025-20004 4.97.20.0015partial
CVE-2025-24305 4.97.20.0014partial
CVE-2024-33617 4.75.90.0046partial
CVE-2024-22374 4.66.50.0016partial
CVE-2025-20022 4.35.70.0022partial
CVE-2026-59384.15.50.0010partial
CVE-2024-37158 3.23.50.0044partial
CVE-2024-25565 3.03.80.0018partial
CVE-2025-47285 1.52.90.0044partial
CVE-2025-47774 1.52.90.0046partial
CVE-2025-3466 5.67.20.0072partial
CVE-2024-9612 5.26.50.0071partial
CVE-2025-1974 9.99.80.9952good
CVE-2024-34144 9.39.80.4808good
CVE-2024-29988 KEV 9.28.80.4515good
CVE-2026-21510 KEV9.28.80.2584good

Other controls in family SC

SC-1 SC-10 SC-11 SC-12 SC-13 SC-14 SC-15 SC-16 SC-17 SC-18 SC-19 SC-20 SC-21 SC-22 SC-23 SC-24 SC-25 SC-26 SC-27 SC-28 SC-29 SC-3 SC-30 SC-31 SC-32 SC-33 SC-34 SC-35 SC-36 SC-37 SC-38 SC-39 SC-4 SC-40 SC-41 SC-42 SC-43 SC-44 SC-45 SC-46 SC-47 SC-48 SC-49 SC-5 SC-50 SC-51 SC-6 SC-7 SC-8 SC-9