This objective requires your organization to identify where security functions—such as authentication, auditing, or access control—are implemented as distinct modules, logically or physically separate from general user functionality. This separation helps reduce risk by isolating sensitive controls from potential tampering or misuse.