That's Not Logical: Segmenation and Security Controls
Everyone looks to CMMC and NIST-SP-800-171 compliance through a lens of finding a technical solution. Buying the perfect tool or adding a pay-to-play enclave.
Systems Security Engineering, however, does not rely on technology alone. Outcomes, not tools, drive compliance. Administrative, procedural, and technical controls all matter in cybersecurity compliance. An organization must understand what a security requirement demands and how an organization demonstrates that it meets that requirement.
Security Requirements
A security requirement establishes an outcome or obligation. A security control achieves that outcome. In CMMC an assessor will check if your controls have the adequacy and sufficiency to meet the 110 NIST-SP-800-171 rev requirements.
For example, a requirement might state that only authorized users may access Controlled Unclassified Information. CUI is information not meant for public release that requires safeguarding or dissemination controls under applicable laws, regulations, or government-wide policies. The requirements does not prescribe a particular product, network architecture, or implementation technology.An organization might satisfy the requirement through access policies, documented workflows, identity and access management technologies, or a combination of all three.
Security Controls
A security control acts a safeguard or countermeasure designed to protect the confidentiality, integrity, or availability of information and information systems.
These three properties form the foundation of information security:
Confidentiality: Preventing unauthorized disclosure of information.
Integrity: Protecting information against unauthorized modification or destruction.
Availability: Ensuring authorized users can access information and systems when needed.
The requirements of NIST-SP-800-171 only demand you have controls to protect the confidentiality of CUI. An organization can utilize three kinds of controls organizations can use to meet cybersecurity requirements: administrative, procedural, and technical controls.
Three Types of Controls
1. Administrative Controls: Establishing the Rules
Administrative controls are management-directed safeguards that establish the organization’s security expectations, authority, responsibilities, and governance. They define who is authorized to do something, under what conditions, and who is responsible for enforcing the rules.
Examples include:
-
Information classification and handling policies
-
Acceptable Use Policies (AUPs)
-
Access authorization policies
-
Personnel screening and authorization
-
Security roles and responsibilities
-
Risk management and governance decisions
Consider an organization handling Controlled Unclassified Information (CUI). The organization establishes a policy stating that CUI may only be processed on specifically authorized company devices and within designated systems. That policy is an administrative control.
It establishes the boundary of authorized behavior, even though the policy itself does not technically prevent someone from violating it.
2. Procedural Controls: Defining How Work Gets Done
Procedural controls are documented or established activities that describe how people implement security requirements in day-to-day operations. A procedure specifies the actions, responsibilities, and sequences necessary to implement an organization’s policies.
Separating Fact and Fiction
Logical separation does not require physical separation, but it does require effective separation.
A single device can be used to access both a commercial environment and a CUI enclave. Administrative controls establish authorized boundaries. Procedural controls direct user behavior. Technical controls provide the enforcement required by the applicable security objectives.
The important question is not whether the organization owns one laptop or two. It is whether the organization can identify, control, and demonstrate the authorized flow of CUI across its defined system boundary.
For example, an organization might establish the following workflow:
-
Employees receive CUI through an approved secure file-sharing service.
-
Employees access that information only from authorized devices.
-
CUI is not downloaded to personal devices.
-
Employees do not transfer CUI into the organization’s commercial email environment.
-
Completed work is returned through the approved service.
These procedures create operational separation between CUI activities and ordinary business activities. A procedure is not automatically effective simply because it has been documented. Employees must follow it, and the organization needs appropriate oversight and evidence. Nevertheless, a well-designed and consistently executed procedure can act as an important security control.
3. Technical Controls: Enforcing Rules Through Technology
Technical controls use hardware, software, firmware, or system configurations to implement or enforce security requirements.
Examples include:
-
Firewalls and network access control lists
-
Multifactor authentication (MFA)
-
Endpoint detection and response (EDR)
-
Encryption
-
Conditional Access policies
-
Data loss prevention (DLP)
-
Virtual local area networks (VLANs)
-
Application allowlisting
A firewall rule that prevents traffic between two network segments is a technical control.
A Conditional Access policy that prevents an unmanaged device from accessing a CUI repository is another. Technical controls are valuable because they can enforce restrictions automatically, reduce reliance on human behavior, and generate evidence of enforcement.But the existence of a technical solution does not mean every requirement demands that particular solution.
You can not meet administrative requirements with technical controls. If you must identify authorized users, technology can not do that for you. If a requirement needs a technical control you can not meet by writing an administrative policy or a procedural controls
Very few NIST-SP-800-171 rev 2 requirements demand technical controls First, requirements are not products. A cybersecurity requirement establishes an obligation, not necessarily a prescribed technology.
Second, administrative, procedural, and technical controls serve different but complementary purposes. No single category should be dismissed without examining what the requirement actually demands.
Third, logical separation is not synonymous with network segmentation. The appropriate means of separation depends on the system boundary, information flows, required enforcement, and applicable assessment objectives.
Logical Separation
Logical separation segregates information, users, resources, or activities through defined access boundaries without necessarily requiring physical separation. Physical separation relies on physically distinct equipment, facilities, or infrastructure.
Logical separation can involve technical mechanisms such as access control permissions, network segmentation, and isolated virtual environments. It can also involve administrative restrictions and operational procedures that limit which people, systems, and workflows are authorized to interact with particular information.
A policy that declares two systems separate does not equal as a mechanism that prevents those systems from communicating. Whether administrative and procedural controls provide sufficient coverage depends on the actual wording of the requirement, the threats being addressed, and the effectiveness of the controls.
Logical Separation on a Single Device: One Laptop, Two Security Environments
A defense contractor does not need two laptops to separate its commercial business environment from its Controlled Unclassified Information (CUI) environment. A single laptop can access both environments while maintaining meaningful logical separation through a combination of administrative, procedural, and technical controls.
Many small companies may have:
- Commercial environment: Microsoft 365 Commercial for ordinary business activities, including email, accounting, scheduling, and Federal Contract Information (FCI).
- CUI enclave: A FedRAMP-authorized cloud environment, such as an appropriately configured Kiteworks repository or Microsoft 365 GCC High, used to store, process, and exchange CUI.
- Endpoint: A single company-managed Windows 11 laptop authorized to access both environments.
An enclave builds a collection of system components operating within an established security boundary and subject to a specified set of security controls. A security boundary identifies the systems, components, interfaces, and information flows subject to a particular set of security requirements. The laptop is a shared access point between the environments. The challenge is preventing CUI from crossing into the commercial environment through unauthorized information flows.
- Administrative controls: Define what the laptop is authorized to do .
The organization establishes a written policy defining two permitted operating contexts. The Acceptable Use Policy prohibits transferring CUI into commercial email, OneDrive, SharePoint, Teams, or other unauthorized applications. The System Security Plan identifies the laptop as a component within the CUI assessment boundary and describes its connections to both environments.
The administrative designation does not create a technical security boundary by itself. It establishes which activities the organization authorizes and provides the governance necessary to assess whether the implementation is appropriate.
- Procedural controls: Separate the workflows
Next, the organization establishes distinct procedures for working in each environment. In the commercial workflow, the employee uses Microsoft 365 Commercial for routine business activities. The employee does not open, upload, attach, or synchronize CUI through those applications. Outlook for Web Access gets used for Commercial work, and Outlook for CUI work. The Commercial environment can only get accessed through Mozilla’s Firefox and the CUI environment in Microsoft Edge.
The organization can establish additional procedures requiring the employee to close commercial applications before beginning CUI work, verify the correct account and destination before transferring files, and report suspected accidental disclosures.
- Technical controls: Enforce the separation
Technical controls strengthen the administrative and procedural restrictions by limiting what can actually happen on the laptop.
Possible safeguards include:
- Endpoint management: Intune enforces device compliance, encryption, security configuration, and application restrictions.
- Identity separation: Different identities, sessions, or browser profiles distinguish commercial and CUI access. Separate profiles help avoid mistakes but do not provide strong OS-level isolation.
- Conditional Access: Entra policies restrict access to approved identities and compliant devices.
- Data loss prevention: Endpoint and cloud DLP policies restrict unauthorized CUI movement where supported and properly configured.
- Application controls: Approved applications and browser restrictions reduce opportunities for unauthorized copying or synchronization.
- Remote processing: CUI remains within an appropriately secured remote application, virtual desktop, or browser-isolated environment, rather than being downloaded to the general-purpose laptop.
A VDI can provide especially strong separation, provided the architecture prevents unauthorized clipboard use, downloads, printing, drive redirection, and other data-transfer paths. A single physical laptop can therefore serve as the access device for two logically separated computing environments.