# SC-04 Information in Shared System Resources — NIST 800-53 Rev5 control

> FedRAMP Consolidated Rules for 2026 v2026.07.14.01 · updated 2026-07-14
> Canonical page: /control/sc-4

Canonical id: `sc-4` · family `SC`

> Prevent unauthorized and unintended information transfer via shared system resources.

_Control title and statement: NIST SP 800-53 Rev5 catalog (the pinned commit is in `/api` under `control_text`). The FedRAMP rules reference these controls by id only; everything below is what FedRAMP says about this id._

## Rev5 baseline membership

- certification class C
- certification class D

## Key Security Indicators that reach it

- `KSI-CNA-ULN` — Using Logical Networking (Cloud Native Architecture)
  Logical networking and related capabilities are used and persistently reviewed to enforce traffic flow controls.
- `KSI-IAM-ELP` — Ensuring Least Privilege (Identity and Access Management)
  Identity and access management measures are used and persistently reviewed to ensure each user or device can only access the resources they need.
- `KSI-PIY-RSD` — Reviewing Security in the SDLC (Policy and Inventory)
  The effectiveness of building security and privacy considerations into the Software Development Lifecycle and aligning with CISA Secure By Design principles is persistently reviewed.
- `KSI-SVC-PRR` — Preventing Residual Risk (Service Configuration)

## FedRAMP guidance

_No FedRAMP-specific guidance attaches to this control._
