NIST SP 800-207
NIST SP 800-207: Access Control

NIST SP 800-207 SP800-207-DEP-SANDBOX: Device Application Sandboxing

Runs vetted applications or processes in sandboxed compartments on the asset, isolating them from the rest of the device and from local attacks.

Other controls in NIST SP 800-207: Access Control

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.