Cyber Resilience

NIST 800-53 r5 · Controls catalogue · Family SC

SC-50Software-enforced Separation and Policy Enforcement

Implement software-enforced separation and policy enforcement mechanisms between {{ insert: param, sc-50_odp }}.

Last updated: 22 August 2026 07:11 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (0)

Weaknesses this control addresses (8)AI-assisted

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-862Missing Authorization10,200+Requires explicit authorization checks as part of the enforced policy between separated components.
CWE-284Improper Access Control6,900+Directly implements software-enforced boundaries that prevent unauthorized access across separated components or domains.
CWE-863Incorrect Authorization3,900+Policy enforcement mechanisms correct or prevent flawed authorization logic across domain boundaries.
CWE-269Improper Privilege Management3,400+Policy enforcement mechanisms limit privilege escalation and improper privilege assignments across boundaries.
CWE-732Incorrect Permission Assignment for Critical Resource1,900+Software-enforced separation ensures correct permission assignments on critical resources between domains.
CWE-285Improper Authorization1,500+Enforces policy-based authorization decisions between the separated subjects and objects.
CWE-250Execution with Unnecessary Privileges300+Separation and policy enforcement reduce the ability to execute with unnecessary privileges by isolating higher-privilege functions.
CWE-653Improper Isolation or Compartmentalization73Explicitly requires isolation and compartmentalization mechanisms that address failures in separating security domains.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2023-42667 5.47.80.0024good
CVE-2023-49141 5.47.80.0029good
CVE-2023-31325 4.97.20.0014good
CVE-2025-54514 3.54.80.0010good
CVE-2024-36332 3.56.80.0010good

Other controls in family SC

SC-1 SC-10 SC-11 SC-12 SC-13 SC-14 SC-15 SC-16 SC-17 SC-18 SC-19 SC-2 SC-20 SC-21 SC-22 SC-23 SC-24 SC-25 SC-26 SC-27 SC-28 SC-29 SC-3 SC-30 SC-31 SC-32 SC-33 SC-34 SC-35 SC-36 SC-37 SC-38 SC-39 SC-4 SC-40 SC-41 SC-42 SC-43 SC-44 SC-45 SC-46 SC-47 SC-48 SC-49 SC-5 SC-51 SC-6 SC-7 SC-8 SC-9