# SC-32 — System Partitioning

- **Control ID:** SC-32
- **Family:** [SC](/md/families/SC.md)
- **Baselines:** No content available.
- **Enhancement of:** No content available.

## Description

Partition the system into \[assignment\] residing in separate \[assignment\] domains or environments based on \[assignment\].

## Discussion

System partitioning is part of a defense-in-depth protection strategy. Organizations determine the degree of physical separation of system components. Physical separation options include physically distinct components in separate racks in the same room, critical components in separate rooms, and geographical separation of critical components. Security categorization can guide the selection of candidates for domain partitioning. Managed interfaces restrict or prohibit network access and information flow among partitioned system components.

## Implementation guidance

No content available.

## CSF 2.0 subcategories

- [PR.DS-01](/md/csf/PR.DS-01.md) — The confidentiality, integrity, and availability of data-at-rest are protected
- [PR.DS-10](/md/csf/PR.DS-10.md) — PR.DS-10

## Related controls

- [AC-4](/md/controls/AC-4.md)
- [AC-6](/md/controls/AC-6.md)
- [SA-8](/md/controls/SA-8.md)
- [SC-2](/md/controls/SC-2.md)
- [SC-3](/md/controls/SC-3.md)
- [SC-7](/md/controls/SC-7.md)
- [SC-36](/md/controls/SC-36.md)

---

Derived from official NIST publications (NIST SP 800-53 Rev 5 and NIST CSF 2.0). nistcontrols.com is not affiliated with NIST.
