Cyber Resilience

NIST 800-53 r5 · Controls catalogue · Family SC

SC-32System Partitioning

Partition the system into {{ insert: param, sc-32_odp.01 }} residing in separate {{ insert: param, sc-32_odp.02 }} domains or environments based on {{ insert: param, sc-32_odp.03 }}.

Last updated: 22 August 2026 07:11 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (1)

Weaknesses this control addresses (8)AI-assisted

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-284Improper Access Control6,900+Enforces separation of domains that reduces the ability to bypass or violate access control boundaries.
CWE-732Incorrect Permission Assignment for Critical Resource1,900+Supports correct permission assignment by allowing permissions to be scoped to individual partitions rather than a monolithic system.
CWE-285Improper Authorization1,500+Partitioning limits authorization scope by confining subjects and objects to distinct environments.
CWE-668Exposure of Resource to Wrong Sphere800+Prevents resources from residing in the wrong sphere by design through explicit domain separation.
CWE-250Execution with Unnecessary Privileges300+Enables execution with minimal necessary privileges by isolating components into distinct environments.
CWE-441Unintended Proxy or Intermediary ('Confused Deputy')100+Mitigates confused deputy risks by ensuring distinct privilege domains so one partition cannot unintentionally act on behalf of another.
CWE-669Incorrect Resource Transfer Between Spheres100+Reduces incorrect transfers between spheres by establishing clear, separate domains for different sensitivities or functions.
CWE-653Improper Isolation or Compartmentalization73Directly implements isolation and compartmentalization by placing components into separate domains or environments.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2025-3466 5.67.20.0072good
CVE-2024-9612 5.26.50.0071good
CVE-2023-38575 4.35.50.0027good
CVE-2023-42667 5.47.80.0024good
CVE-2023-49141 5.47.80.0029good
CVE-2023-31325 4.97.20.0014good
CVE-2019-25655 4.76.20.0016partial
CVE-2025-54514 3.54.80.0010good
CVE-2024-36332 3.56.80.0010good
CVE-2025-1974 9.99.80.9952good
CVE-2025-21590 KEV 7.54.40.0171good
CVE-2024-33768 7.49.80.0085good
CVE-2026-4692 7.410.00.0049good
CVE-2026-44008 7.49.80.0085good
CVE-2026-534217.49.80.0068good
CVE-2026-534057.39.80.0044good
CVE-2026-630717.39.80.0044good
CVE-2026-0542 7.09.20.0062good
CVE-2025-4083 6.89.10.0043good
CVE-2025-57738 6.87.20.2311good
CVE-2026-12297 6.79.60.0039good
CVE-2025-5476 6.58.80.0031good
CVE-2025-12805 6.18.10.0038good
CVE-2026-157386.08.50.0037good
CVE-2024-23683 5.88.20.0036good

Other controls in family SC

SC-1 SC-10 SC-11 SC-12 SC-13 SC-14 SC-15 SC-16 SC-17 SC-18 SC-19 SC-2 SC-20 SC-21 SC-22 SC-23 SC-24 SC-25 SC-26 SC-27 SC-28 SC-29 SC-3 SC-30 SC-31 SC-33 SC-34 SC-35 SC-36 SC-37 SC-38 SC-39 SC-4 SC-40 SC-41 SC-42 SC-43 SC-44 SC-45 SC-46 SC-47 SC-48 SC-49 SC-5 SC-50 SC-51 SC-6 SC-7 SC-8 SC-9