DKDavid Koran& Associates
Home The CMMC Guide Part III · System and Communications Protection SC.L2-3.13.4
The CMMC Guide · System and Communications Protection Family

SC.L2-3.13.4  Prevent Unauthorized Transfer via Shared Resources

Prevent unauthorized and unintended information transfer via shared system resources.

Family
System and Communications ProtectionSC, 16 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
OnePer NIST SP 800-171A

1Overview

SC.L2-3.13.4 addresses information leaking between users through shared system resources. It requires that unauthorized and unintended information transfer via shared system resources be prevented, so that data left in memory, storage, or other shared resources by one process or user is not exposed to another. It is a one-point requirement and may be deferred on a plan of action.

Systems share resources, memory, storage, buffers, among processes and users, and if those resources are not cleared or isolated between uses, information from one can leak to the next. This control requires preventing that unauthorized and unintended transfer, so that a shared resource does not carry one user's data to another. It is typically addressed by the operating system and platform through resource isolation and clearing, but the organization is responsible for ensuring the property holds. The single assessment objective is that this transfer is prevented.

The requirement · NIST SP 800-171 Rev 2, 3.13.4

Prevent unauthorized and unintended information transfer via shared system resources.

The requirement is to prevent information transfer, both unauthorized and unintended, through shared system resources. In practice this means the platform clears or isolates shared resources such as memory and storage between uses, so residual data does not pass from one process or user to another. Modern operating systems provide much of this, and the organization ensures the systems in scope actually enforce it.

2The Assessment Objective

NIST SP 800-171A frames 3.13.4 as a single objective: prevent unauthorized and unintended transfer via shared resources.

Unauthorized and unintended information transfer via shared system resources is prevented. Shared resources do not leak data between users or processes.

MeetsShared resources are cleared or isolated so information does not transfer between uses.
FailsResidual data in shared resources is exposed to other users or processes.

The single objective is preventing the transfer. The common gap is systems that do not enforce resource isolation, or legacy platforms where clearing is not assured. The assessor looks for evidence that shared resources do not leak information between uses.

3Failure Patterns

The failures are about residual data in shared resources.

Resources not cleared between uses

Where memory or storage is reassigned without clearing, one user's data can appear to the next. Clearing or isolating shared resources prevents the transfer.

Isolation not enforced

Platforms that do not enforce process or user isolation allow shared resources to carry data across boundaries. Enforced isolation closes this.

Legacy systems without the property

Older systems may not assure resource clearing, leaving the transfer possible. Systems in scope have to actually enforce the prevention.

The common root
This control fails quietly, because shared-resource leakage is invisible in normal use. Nothing appears wrong until residual data surfaces where it should not, so the property has to be assured by the platform rather than noticed by users. Ensuring the systems in scope enforce isolation is what prevents the leak.

4Ownership

This is an IT and platform-owned control.

RoleResponsibility for this control
IT and system administratorEnsures systems enforce resource isolation and clearing. Owns the configuration evidence.
System architectsSelect platforms that provide the isolation property.
Security or compliance leadConfirms the prevention holds on systems in scope.
See also: This control complements the separation of SC.L2-3.13.3 and the security engineering of SC.L2-3.13.2.

5Tooling

The control is delivered largely by the operating system and platform.

ObjectiveToolingWhat it provides
isolateOS process and memory isolationSeparation of shared resources between users and processes.
clearResource clearing on reallocationResidual data removed before reuse.

The caveat is that the property has to actually hold on the systems in scope, especially any legacy platforms. Assuming modern isolation without confirming it on older systems leaves a gap. The assessor examines whether the transfer is prevented, so the property has to be enforced.

6Evidence

The satisfied version of 3.13.4 shows shared resources that do not leak.

EvidenceWhat it demonstrates
Platform isolation configurationThe objective. Shared resources isolated and cleared.
System documentationThe objective. The prevention property on systems in scope.

The evidence should show that systems in scope enforce isolation and clearing of shared resources so information does not transfer between uses. The platform configuration and system documentation are the clearest demonstration of the control.

A shared resource should not carry data between users

Residual data in memory or storage can leak from one user to the next unless the platform prevents it, so this control asks that unauthorized and unintended transfer via shared resources be stopped. Confirming that property on the systems in scope is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.13.4. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.13.4. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in System and Communications Protection
SC.L2-3.13.3 · Separate User and Management Functionality
Next in System and Communications Protection →
SC.L2-3.13.5 · Public-Access Subnetworks
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry SC.L2-3.13.4 · Edition 2026.1 · Last reviewed July 12, 2026