This objective ensures that your organization has formally documented where and how key security functions are isolated from general user functionality. These functions must be clearly identified and described in your policies, architecture diagrams, or System Security Plan (SSP), especially where they protect Controlled Unclassified Information (CUI).