Skip to main content
Version: 2026.07

Cybersecurity Shared Responsibility Model

Overview

Our Cybersecurity Shared Responsibility Model is designed to provide a comprehensive approach to security and compliance by clearly defining control ownership across the application environment. This model explicitly highlights the shared nature of cybersecurity, encompassing controls supported by Istari Digital and the Customer.

The model divides security controls into three distinct categories, clearly indicating the implementation responsibility:

  • Inherited: Security controls managed entirely by Istari Digital, which the customer benefits from without direct action.
  • Customer: Security controls that the customer is solely responsible for implementing and maintaining within their environment.
  • Hybrid: Controls with shared responsibilities, requiring a combination of efforts from Istari Digital and the Customer to implement specific security aspects.

Figure 3.1: Security Control Allocation by Responsibility Figure 3.1: Security Control Allocation by Responsibility

These controls serve as a foundation for shared responsibility discussions and may be adjusted based on specific customer cybersecurity requirements. Istari Digital will consistently review these controls and notify the customer if the status of any Shared Responsibility changes.

The control alignment for the Cybersecurity Shared Responsibility Model is based on the Cybersecurity Maturity Model Certification (CMMC) Level 2 process and governed by the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Revision 3 framework.

Inherited Controls

These are security controls that customers inherit from the Istari Platform. Customers benefit from these controls without direct action, as they are embedded in the service provided by Istari Digital.

ControlControl TitleImplementation Narrative
IA.L2-3.5.10Cryptographically Protected PasswordsThe Istari Digital Platform obscures and encrypts passwords used in conjunction with the Istari Platform.
IA.L2-3.5.11Obscure FeedbackThe Istari Digital Platform obscures feedback for unauthorized login attempts.
SC.L2-3.13.2Security EngineeringIstari Digital manages our software development lifecycle using a DevSecOps approach, including the following software release activities: Unit/Integration Testing (Requires 80% Code Coverage to meet Government Certification to Field requirement); Dependency Check and Container Scans (Involves scanning against Common Vulnerability Scoring System findings with a manual review for anything higher than 7); Secrets Detection; Static Code and Quality Analysis; Artifact Signing.
IA.L2-3.5.4Replay-Resistant AuthenticationAuthentication is handled with a combination of a single use session token and the credentialing hash. Both components are required for an authenticated request.
SI-L2-3.14.3Security Alerts & AdvisoriesIstari Digital receives security alerts and advisories relevant to its operations. Should Istari Digital software be affected, appropriate notification pipelines will be activated, and the customer will be informed as necessary, in accordance with established service level agreements (SLAs).

Hybrid Controls

This category signifies a shared responsibility between the customer and Istari Digital, where Istari Digital typically provides the capability and the customer is responsible for its configuration and use. Istari Digital provides the platform or feature, but the customer must configure it or use it correctly.

ControlControl TitleImplementation Narrative
AC.L2-3.1.9Privacy & Security NoticesThe Istari Digital Platform provides the customer with configurable banners consistent with the requirements of this control which must be set by the system owner upon deployment.
CM.L2-3.4.2Security Configuration EnforcementThe Istari Digital Platform maintains a system baseline for platform configurations, published at https://docs.istaridigital.com/releases/. Customers are responsible for configuration and maintenance of their respective infrastructure.
IA.L2-3.5.5Identifier ReuseIstari supplements the customer's capability by establishing Unique Unit Identifiers (UUIDs) for every piece of data and its subcomponents that are registered with the Istari platform. This ensures a consistent and traceable baseline for all digital assets. Customers are responsible for configuration of system identifiers for their respective infrastructure.
AC.L1-3.1.1Authorized Access ControlThe Istari Digital Platform utilizes Zitadel (Identity) and Spice DB (Authorization) for identity and access management (IAM), implemented locally within the Control Plane. These IAM controls rely on role-based access, allowing for granular adjustments specific to each model within the platform. Customers are responsible for configuring and maintaining appropriate access controls once the Platform is deployed in their environment.
AC.L2-3.1.3Control CUI FlowThe Istari Digital Platform restricts system services from accessing data in a manner that could potentially expose the protected models. With the use of single use/signed URLs and various encryption methods, protected models can only be accessed by approved tools and services within the Data Plane. This is also limited to authorized end users of the platform as configured by the customer. Customers are responsible for making sure their data is labeled appropriately.
AC.L2-3.1.10Session LockIstari Digital enables automated session locks through the Istari Admin Panel. The customer is responsible for adjusting the control settings to meet their needs.
AT.L2-3.2.1Role-based Risk AwarenessRecommendations for this control include all Defense and Industrial Base and Government users completing the following training or equivalent prior to receiving access to the Istari Digital Platform Environment:
1) Security Awareness: https://securityawareness.usalearning.gov/cybersecurity/index.htm
2) CUI: https://securityawareness.usalearning.gov/cui/index.html
3) Insider Threat: https://securityawareness.usalearning.gov/itawareness/index.htm.
While Istari Digital maintains its own acceptable use and training policy consistent with the above recommendations, the customer is responsible for controlling access and maintaining training requirements on their systems.
AT.L2-3.2.2Role-based TrainingRecommendations for this control include all Defense and Industrial Base and Government users completing the following training or equivalent prior to receiving access to the Istari Digital Platform Environment:
1) Security Awareness: https://securityawareness.usalearning.gov/cybersecurity/index.htm
2) CUI: https://securityawareness.usalearning.gov/cui/index.html
3) Insider Threat: https://securityawareness.usalearning.gov/itawareness/index.htm.
While Istari Digital maintains its own acceptable use and training policy consistent with the above recommendations, the customer is responsible for controlling access and maintaining training requirements on their systems.
AT.L2-3.2.3Insider Threat AwarenessRecommendations for this control include all Defense and Industrial Base and Government users completing the following training or equivalent prior to receiving access to the Istari Digital Platform Environment:
1) Security Awareness: https://securityawareness.usalearning.gov/cybersecurity/index.htm
2) CUI: https://securityawareness.usalearning.gov/cui/index.html
3) Insider Threat: https://securityawareness.usalearning.gov/itawareness/index.htm.
While Istari Digital maintains its own acceptable use and training policy consistent with the above recommendations, the customer is responsible for controlling access and maintaining training requirements on their systems.
CM.L2-3.4.1System BaseliningThe Istari Digital Platform maintains a system baseline for platform configurations, published at https://docs.istaridigital.com/releases/. Customers are responsible for configuration and maintenance of their respective infrastructure.
CM.L2-3.4.6Least FunctionalityIstari Digital continually ensures that native systems and services operate with only the minimum functionality required to effectively complete authorized and necessary actions. Additional configurations may be required based on requirements of the customer environment to limit nonessential actions and enforce the principle of least privilege.
CM.L2-3.4.7Nonessential FunctionalityIstari Digital continually ensures that native systems and services operate with only the minimum functionality required to effectively complete authorized and necessary actions. Additional configurations may be required based on requirements of the customer environment to limit nonessential actions and enforce the principle of least privilege.
CM.L2-3.4.8Application Execution PolicyIstari Digital continually ensures that native systems and services operate with only the minimum functionality required to effectively complete authorized and necessary actions. Additional configurations may be required based on requirements of the customer environment to limit nonessential actions and enforce the principle of least privilege.
IA.L1-3.5.1IdentificationThe Istari Platform implements identity and access management controls using Zitadel. Customers are responsible for configuring and maintaining appropriate access controls once the Platform is deployed in their environment.
IA.L1-3.5.2AuthenticationThe Istari Digital Platform supports the use of Multi-Factor Authentication (MFA). Customers are responsible for configuring and maintaining appropriate access controls once the Platform is deployed in their environment.
IA.L2-3.5.3Multifactor AuthenticationThe Istari Digital Platform supports the use of Multi-Factor Authentication (MFA). Customers are responsible for configuring and maintaining appropriate access controls once the Platform is deployed in their environment.
IR-L2-3.6.1Incident HandlingIstari Digital maintains an operational incident-handling capability for its systems, encompassing preparation, analysis, containment, and recovery. We also identify vulnerabilities within the software development pipeline and communicate necessary patches. Customers are notified of any vulnerabilities affecting their systems in accordance with established service level agreements. The customer is responsible for responding to their environment, including tracking, documenting, and internally reporting incidents, as well as communicating them between organizations when necessary.
IR-L2-3.6.2Incident ReportingIstari Digital maintains an operational incident-handling capability for its systems, encompassing preparation, analysis, containment, and recovery. We also identify vulnerabilities within the software development pipeline and communicate necessary patches. Customers are notified of any vulnerabilities affecting their systems in accordance with established service level agreements. The customer is responsible for responding to their environment, including tracking, documenting, and internally reporting incidents, as well as communicating them between organizations when necessary.
IR-L2-3.6.3Incident Response TestingIstari Digital maintains an operational incident-handling capability for its systems, encompassing preparation, analysis, containment, and recovery. We also identify vulnerabilities within the software development pipeline and communicate necessary patches. Customers are notified of any vulnerabilities affecting their systems in accordance with established service level agreements. The customer is responsible for responding to their environment, including tracking, documenting, and internally reporting incidents, as well as communicating them between organizations when necessary.
PS.L2-3.9.1Screen IndividualsIstari Digital currently implements an onboarding/offboarding system that includes personnel screening, background checks and certification of appropriate citizenship status. This is maintained for as long as access is required. Customers are responsible for implementing their own process to screen individuals that have access to the Istari Platform.
PS.L2-3.9.2Personnel ActionsIstari Digital currently implements an onboarding/offboarding system that includes personnel screening, background checks and certification of appropriate citizenship status. This is maintained for as long as access is required. Customers are responsible for implementing their own process to screen individuals that have access to the Istari Platform.
SC.L2-3.13.3Role SeparationIstari Digital has configured the platform for user functionality and system management to be identified through two different authentication pipelines. Customers are responsible for implementing their user base to utilize those mechanisms.
SC.L2-3.13.4Shared Resource ControlIstari Digital's Platform integrates microsegmentation of data with controlled access permissioned to respect individual user access, data sensitivity, and overarching handling caveats. In addition, the Platform's multitenancy capability enables data segregation. Customers are responsible for ensuring resources are appropriately configured.
SC.L2-3.13.8Data in TransitThe Istari Platform is built to run off FIPS validated encryption algorithms such as TLS. Communication from the agent to the platform is configured to work over Port 443. Customers are responsible for ensuring encryption configurations are appropriately set.
SC.L2-3.13.11CUI EncryptionThe Istari Platform is built to run off FIPS validated encryption algorithms such as TLS. Communication from the agent to the platform is configured to work over Port 443. Customers are responsible for ensuring encryption configurations are appropriately set.
SC.L2-3.13.15Communications AuthenticityIstari protects the authenticity of communication sessions by implementing the following: Transport Layer Security (TLS) protocol; Multifactor Authentication required for system login. Customers are responsible for ensuring communication authenticity is appropriately configured for their systems.
SC.L2-3.13.16Data at RestThe Istari Digital Platform supports Data at Rest Encryption. Customers are responsible for ensuring organizational key management is in place to leverage this capability.
SI-L1-3.14.1Flaw RemediationIstari Digital conducts monthly risk and vulnerability assessments as part of its software development lifecycle. If a vulnerability is identified, an appropriate notification will be provided to all relevant stakeholders in accordance with service level agreements (SLAs) to support informed risk management. Customers are responsible for implementing timely system patches to maintain a compliant risk posture.
SI-L1-3.14.2Malicious Code ProtectionIstari Digital maintains malicious code protection within the backend of the platform. Customers are responsible for ensuring their systems have the same protection and that the data they process through the Istari Platform is safe.
SI-L1-3.14.4Update Malicious Code ProtectionIstari Digital maintains malicious code protection within the platform's backend. Customers are responsible for ensuring their own systems have equivalent protection and that the data they process through the Istari Platform is secure.
AC.L2-3.1.12Control Remote AccessCustomers are responsible for managing all external connections and the associated network encryption. Istari enhances data segregation using Istari Secure Connection Service and Multitenancy features. This is achieved by allowing the configuration of unique access tokens and one-way trust relationships to restrict access to sensitive data.
AC.L2-3.1.13Remote Access ConfidentialityCustomers are responsible for managing all external connections and the associated network encryption. Istari enhances data segregation using Istari Secure Connection Service and Multitenancy features. This is achieved by allowing the configuration of unique access tokens and one-way trust relationships to restrict access to sensitive data.
AC.L2-3.1.15Privileged Remote AccessCustomers are responsible for managing all external connections and the associated network encryption. Istari enhances data segregation using Istari Secure Connection Service and Multitenancy features. This is achieved by allowing the configuration of unique access tokens and one-way trust relationships to restrict access to sensitive data.
AC.L1-3.1.2Transaction & Function ControlThe customer is responsible for managing access and separation of duties for roles configured on their deployment of the Istari Platform. Istari augments the customer's existing identity and access management by utilizing Zitadel for access control, which enables fine-grained data permissioning.
AC.L2-3.1.4Separation of DutiesThe customer is responsible for managing access and separation of duties for roles configured on their deployment of the Istari Platform. Istari augments the customer's existing identity and access management by utilizing Zitadel for access control, which enables fine-grained data permissioning.
AC.L2-3.1.5Least PrivilegeThe customer is responsible for managing access and separation of duties for roles configured on their deployment of the Istari Platform. Istari augments the customer's existing identity and access management by utilizing Zitadel for access control, which enables fine-grained data permissioning.
AC.L2-3.1.6Non-Privilege Account UseThe customer is responsible for managing access and separation of duties for roles configured on their deployment of the Istari Platform. Istari augments the customer's existing identity and access management by utilizing Zitadel for access control, which enables fine-grained data permissioning.
AC.L2-3.1.7Privileged FunctionsThe customer is responsible for managing access and separation of duties for roles configured on their deployment of the Istari Platform. Istari augments the customer's existing identity and access management by utilizing Zitadel for access control, which enables fine-grained data permissioning.
AC.L2-3.1.20External ConnectionsCustomers are responsible for managing all external connections and the associated network encryption. Istari enhances data segregation using Istari Secure Connection Service and Multitenancy features. This is achieved by allowing the configuration of unique access tokens and one-way trust relationships to restrict access to sensitive data.
IA.L2-3.5.7Password ComplexityThe customer is responsible for configuring their deployment of the Istari Platform. Istari augments the customer's existing identity and access management by utilizing Zitadel for access control, which enables fine-grained data permissioning.
IA.L2-3.5.8Password ReuseThe customer is responsible for configuring their deployment of the Istari Platform. Istari augments the customer's existing identity and access management by utilizing Zitadel for access control, which enables fine-grained data permissioning.
IA.L2-3.5.9Temporary PasswordsThe customer is responsible for configuring their deployment of the Istari Platform. Istari augments the customer's existing identity and access management by utilizing Zitadel for access control, which enables fine-grained data permissioning.
RA.L2-3.11.1Risk AssessmentsIstari Digital supports customer system authorization requirements by providing access to Istari Platform software security scans. This facilitates customer-informed approval for system assessments and changes, as well as configuration updates.
RA.L2-3.11.2Vulnerability ScanIstari Digital supports customer system authorization requirements by providing access to Istari Platform software security scans. This facilitates customer-informed approval for system assessments and changes, as well as configuration updates.
RA.L2-3.11.3Vulnerability RemediationIstari Digital supports customer system authorization requirements by providing access to Istari Platform software security scans. This facilitates customer-informed approval for system assessments and changes, as well as configuration updates.

Customer Controls

The remaining controls are the customer's responsibility. They include securing customer data, customer tenant environments, client-side data encryption and integrity, and the security of customer-created or managed applications. The customer must implement these controls to ensure their data is appropriately protected.

ControlControl TitleImplementation Narrative
SI-L1-3.14.5System & File ScanningIstari Digital maintains malicious code protection within the platform's backend. Customers are responsible for ensuring their own systems have equivalent protection and that the data they process through the Istari Platform is secure.
SI-L2-3.14.6Monitor Communications for AttacksAll Istari Platform-driven interactions are captured via standard OpenTelemetry (OTel) logging. These comprehensive logs are available for ingestion by the customer's Security Information and Event Management (SIEM) tool of choice, ensuring a complete audit trail for accountability. Customers are responsible for configuring SIEM solutions to monitor logs.
SI-L2-3.14.7Identify Unauthorized UseAll Istari Platform-driven interactions are captured via standard OpenTelemetry (OTel) logging. These comprehensive logs are available for ingestion by the customer's Security Information and Event Management (SIEM) tool of choice, ensuring a complete audit trail for accountability. Customers are responsible for configuring SIEM solutions to monitor logs.
AC.L2-3.1.11Session TerminationIstari enables configuration of session termination settings within the Istari Platform Admin console. Customers are responsible for setting session timeouts in accordance with relevant cybersecurity standards.
MA.L2-3.7.1Perform MaintenanceCustomers are responsible for configuration and maintenance of their respective infrastructure.
MA.L2-3.7.2System Maintenance ControlCustomers are responsible for configuration and maintenance of their respective infrastructure.
MA.L2-3.7.3Equipment SanitizationCustomers are responsible for configuration and maintenance of their respective infrastructure.
MA.L2-3.7.4Media InspectionCustomers are responsible for configuration and maintenance of their respective infrastructure.
MA.L2-3.7.5Nonlocal MaintenanceCustomers are responsible for configuration and maintenance of their respective infrastructure.
MA.L2-3.7.6Maintenance PersonnelCustomers are responsible for configuration and maintenance of their respective infrastructure.
MP.L2-3.8.1Media ProtectionCustomers are responsible for configuration and maintenance of their respective infrastructure.
MP.L2-3.8.2Media AccessCustomers are responsible for configuration and maintenance of their respective infrastructure.
MP.L1-3.8.3Media DisposalCustomers are responsible for configuration and maintenance of their respective infrastructure.
MP.L2-3.8.4Media MarkingsCustomers are responsible for configuration and maintenance of their respective infrastructure.
MP.L2-3.8.5Media AccountabilityCustomers are responsible for configuration and maintenance of their respective infrastructure.
MP.L2-3.8.6Portable Storage EncryptionCustomers are responsible for configuration and maintenance of their respective infrastructure.
MP.L2-3.8.7Removable MediaCustomers are responsible for configuration and maintenance of their respective infrastructure.
MP.L2-3.8.8Shared MediaCustomers are responsible for configuration and maintenance of their respective infrastructure.
MP.L2-3.8.9Protect BackupsCustomers are responsible for configuration and maintenance of their respective infrastructure.
PE.L1-3.10.1Limit Physical AccessCustomers are responsible for configuration and maintenance of their respective infrastructure.
PE.L2-3.10.2Monitor FacilityCustomers are responsible for configuration and maintenance of their respective infrastructure.
PE.L1-3.10.3Escort VisitorsCustomers are responsible for configuration and maintenance of their respective infrastructure.
PE.L1-3.10.4Physical Access LogsCustomers are responsible for configuration and maintenance of their respective infrastructure.
PE.L1-3.10.5Manage Physical AccessCustomers are responsible for configuration and maintenance of their respective infrastructure.
PE.L2-3.10.6Alternative Work SitesCustomers are responsible for configuration and maintenance of their respective infrastructure.
SC.L2-3.13.13Mobile CodeCustomers are responsible for configuration of their infrastructure to limit the use of mobile code.
AC.L2-3.1.8Unsuccessful Logon AttemptsZitadel enables setting of system limits on the number of failed logon attempts. Customers are responsible for configuration to meet their system needs.
AC.L2-3.1.14Remote Access RoutingCustomers are responsible for Remote Access Routing.
AC.L2-3.1.16Wireless Access AuthorizationCustomers are responsible for configuration of wireless and mobile devices.
AC.L2-3.1.17Wireless Access ProtectionCustomers are responsible for configuration of wireless and mobile devices.
AC.L2-3.1.18Mobile Device ConnectionCustomers are responsible for configuration of wireless and mobile devices.
AC.L2-3.1.19Encrypt CUI on mobileCustomers are responsible for configuration of wireless and mobile devices.
AC.L2-3.1.21Portable Storage UseCustomers are responsible for Portable Storage Use.
AC.L2-3.1.22Control Public InformationCustomers are responsible for Control of their Public Information.
AU-L2-3.3.1System AuditingIstari supports the customer's auditing and accountability requirements by providing standard OpenTelemetry (OTel) logging for all Istari Platform-driven interactions. These comprehensive logs are available for ingestion by the customer's Security Information and Event Management (SIEM) tool of choice, ensuring a complete audit trail for accountability.
AU-L2-3.3.2User AccountabilityIstari supports the customer's auditing and accountability requirements by providing standard OpenTelemetry (OTel) logging for all Istari Platform-driven interactions. These comprehensive logs are available for ingestion by the customer's Security Information and Event Management (SIEM) tool of choice, ensuring a complete audit trail for accountability.
AU-L2-3.3.3Event ReviewIstari supports the customer's auditing and accountability requirements by providing standard OpenTelemetry (OTel) logging for all Istari Platform-driven interactions. These comprehensive logs are available for ingestion by the customer's Security Information and Event Management (SIEM) tool of choice, ensuring a complete audit trail for accountability.
AU-L2-3.3.4Audit Failure AlertingIstari supports the customer's auditing and accountability requirements by providing standard OpenTelemetry (OTel) logging for all Istari Platform-driven interactions. These comprehensive logs are available for ingestion by the customer's Security Information and Event Management (SIEM) tool of choice, ensuring a complete audit trail for accountability.
AU-L2-3.3.5Audit CorrelationIstari supports the customer's auditing and accountability requirements by providing standard OpenTelemetry (OTel) logging for all Istari Platform-driven interactions. These comprehensive logs are available for ingestion by the customer's Security Information and Event Management (SIEM) tool of choice, ensuring a complete audit trail for accountability.
AU-L2-3.3.6Reduction & ReportingIstari supports the customer's auditing and accountability requirements by providing standard OpenTelemetry (OTel) logging for all Istari Platform-driven interactions. These comprehensive logs are available for ingestion by the customer's Security Information and Event Management (SIEM) tool of choice, ensuring a complete audit trail for accountability.
AU-L2-3.3.7Authoritative Time SourceIstari supports the customer's auditing and accountability requirements by providing standard OpenTelemetry (OTel) logging for all Istari Platform-driven interactions. These comprehensive logs are available for ingestion by the customer's Security Information and Event Management (SIEM) tool of choice, ensuring a complete audit trail for accountability.
AU-L2-3.3.8Audit ProtectionIstari supports the customer's auditing and accountability requirements by providing standard OpenTelemetry (OTel) logging for all Istari Platform-driven interactions. These comprehensive logs are available for ingestion by the customer's Security Information and Event Management (SIEM) tool of choice, ensuring a complete audit trail for accountability.
AU-L2-3.3.9Audit ManagementIstari supports the customer's auditing and accountability requirements by providing standard OpenTelemetry (OTel) logging for all Istari Platform-driven interactions. These comprehensive logs are available for ingestion by the customer's Security Information and Event Management (SIEM) tool of choice, ensuring a complete audit trail for accountability.
CA.L2-3.12.1Security Control AssessmentIstari Digital supports customer system authorization requirements by providing access to Istari Platform software security scans. This facilitates customer-informed approval for system assessments and changes, as well as configuration updates.
CA.L2-3.12.2Plan of Action and MilestonesIstari Digital supports customer system authorization requirements by providing access to Istari Platform software security scans. This facilitates customer-informed approval for system assessments and changes, as well as configuration updates.
CA.L2-3.12.3Security Control MonitoringIstari Digital supports customer system authorization requirements by providing access to Istari Platform software security scans. This facilitates customer-informed approval for system assessments and changes, as well as configuration updates.
CA.L2-3.12.4System Security PlanIstari Digital supports customer system authorization requirements by providing access to Istari Platform software security scans. This facilitates customer-informed approval for system assessments and changes, as well as configuration updates.
CM.L2-3.4.3System Change ManagementIstari Digital supports customer system authorization requirements by providing access to Istari Platform software security scans. This facilitates customer-informed approval for system assessments and changes, as well as configuration updates.
CM.L2-3.4.4Security Impact AnalysisIstari Digital supports customer system authorization requirements by providing access to Istari Platform software security scans. This facilitates customer-informed approval for system assessments and changes, as well as configuration updates.
CM.L2-3.4.5Access Restrictions for ChangeIstari Digital supports customer system authorization requirements by providing access to Istari Platform software security scans. This facilitates customer-informed approval for system assessments and changes, as well as configuration updates.
CM.L2-3.4.9User-Installed SoftwareIstari Digital supports customer system authorization requirements by providing access to Istari Platform software security scans. This facilitates customer-informed approval for system assessments and changes, as well as configuration updates.
IA.L2-3.5.6Identifier HandlingThe customer is responsible for configuring their deployment of the Istari Platform. Istari augments the customer's existing identity and access management by utilizing Zitadel for access control, which enables fine-grained data permissioning.
SC.L1-3.13.1Boundary ProtectionBoundary protections and configurations are the customer's responsibility, consistent with their organization's risk posture.
SC.L1-3.13.5Public-Access System SeparationBoundary protections and configurations are the customer's responsibility, consistent with their organization's risk posture.
SC.L2-3.13.6Network Communication by ExceptionBoundary protections and configurations are the customer's responsibility, consistent with their organization's risk posture.
SC.L2-3.13.7Split TunnelingBoundary protections and configurations are the customer's responsibility, consistent with their organization's risk posture.
SC.L2-3.13.9Connections TerminationBoundary protections and configurations are the customer's responsibility, consistent with their organization's risk posture.
SC.L2-3.13.10Key ManagementBoundary protections and configurations are the customer's responsibility, consistent with their organization's risk posture.
SC.L2-3.13.12Collaborative Device ControlBoundary protections and configurations are the customer's responsibility, consistent with their organization's risk posture.
SC.L2-3.13.14Voice over Internet Protocol (VoIP)Not Applicable. Istari does not integrate with VoIP devices.