Skip to content
ControlVerdict
SC.L2-3.13.4addresses
SC.L2-3.13.4Shared Resource Control
Prevent unauthorized and unintended information transfer via shared system resources.
  • [a]

    unauthorized and unintended information transfer via shared system resources is prevented.

View full control

Non-persistent VDI, per-user scratch space, and purged print spools between users

ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
Community is just starting — add yours. No verdicts yet.

Implementation

AO coverage. Addresses the single Shared Resource Control objective for the shared resources this organization actually operates.

Shared resources enumerated. VDI pool desktops, hypervisor memory and datastore blocks, the print/scan spool tier, scratch space on the simulation cluster, and clipboard/drive redirection inside remote sessions. The enumeration is part of the pattern because “shared system resources” is otherwise too abstract to test.

VDI. Pool desktops are non-persistent and reverted to the gold image at logoff, so a later user cannot read the prior user's profile, browser cache, or temporary CAD exports. User profile data lives in the labeled store, not on the pool disk. Idle sessions are logged off rather than left disconnected so the reset actually happens.

Hypervisor and storage. Memory pages are scrubbed on VM power-off where the platform supports it, and transparent page sharing is disabled between VMs in different security tiers. A datastore volume is never re-presented from the enclave tier to the corporate tier without a full wipe; the reverse direction is also blocked by policy.

Print and scan. Spool files are deleted on job completion, the spool directory ACL denies interactive users, and the multifunction devices used for CUI have secure release (job holds until the user badges in) so pages do not sit in the tray. Scan-to-email destinations are limited to the sender.

Compute scratch and redirection. Cluster scratch directories are per-user, mode 0700, and removed by job teardown. Clipboard and drive redirection are disabled for sessions that cross security tiers, so a copy from an enclave session cannot land on a corporate desktop.

Maintenance. Quarterly residue test: log in as a second user immediately after a first user's enclave session on a pool desktop and confirm no profile, cache, temp file, or clipboard content survives. The result is a checklist with the tester's name.

Accepted gap. One large-format plotter has an internal disk that cannot be purged on demand. It lives on the print VLAN, is used only for unmarked drawings by procedure, and its disk is physically destroyed at end of life under the media sanitization SOP.

What the evidence looks like

  • Enumerated list of shared resources in scope
  • VDI pool configuration showing non-persistent desktops and reset on logoff
  • Hypervisor settings for memory scrub and disabled cross-tier page sharing
  • Print server spool purge configuration and secure-release setting
  • Quarterly residue test checklist with results

Environment

Small engineering firm that bursts simulation work onto a shared VDI pool and shares a print/scan tier across office and enclave users.

Tools

Was this example useful?

Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.

Discussion(0)

No discussion on this example yet

Verdicts capture a conclusion. Use a thread when the interesting part is the argument.

Sign in to start a thread.