3.13 System & Communications Protection1 ptPOA&M-eligible

3.13.4 — Stop data leaking through shared resources

Prevent unauthorized and unintended information transfer via shared system resources.

Make sure one user or process can't read leftover CUI from shared memory, cache, or storage.

What it actually means

Shared system resources — memory, cache, temporary storage — shouldn't let information leak from one user or process to another. On modern, supported operating systems this is largely handled by built-in object-reuse protections, so the practical task is to run current, patched operating systems and not disable those protections.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.

Calculate your SPRS score →Draft your SSP language →

Connected requirements

More in System & Communications Protection (3.13)

← Back to the Control Library

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.