Disable Physical Ports

Physical data connection, debug, programming, and maintenance interfaces (e.g., joint test action group (JTAG)) that are not required for spacecraft operations must be disabled, removed, or otherwise made inaccessible before spacecraft operations begin. Interfaces required for operational functions must be explicitly identified and protected against unauthorized physical access and use. These interfaces, essential during development for programming, debugging, and testing, represent persistent attack surfaces in the operational environment: an adversary with physical access to the spacecraft before launch, during ground handling, or at a shared launch facility could exploit active debug interfaces to read memory, modify firmware, bypass security controls, or implant persistent malicious code without leaving detectable traces in software-visible logs. Disabling or removing unused physical interfaces closes a direct hardware-access pathway and reduces reliance on procedural controls or physical security alone. The capability to disable these interfaces must be designed into the system from the outset, as physical removal or reliable hardware-enforced disablement cannot be easily retrofitted into a completed board design.

ID: CM0037
Tier: II
Onboard SV CM 
Created: 2022/10/19
Last Modified: 2026/08/06

Pre-Operations Government

Acquisition requirements should mandate that spacecraft hardware designs include the capability to disable or remove physical debug, programming, maintenance, and other data interfaces that are not authorized for operational use. The disposition of each interface and its disablement method should be documented in the system security architecture and subject to government review. Requirements should specify hardware-enforced or physical disablement where feasible, particularly for interfaces that are not intended to be reactivated after integration. Software-only disablement should not be relied upon when an adversary with physical access could bypass or reverse the configuration. Contract language should require contractors to document every physical port and debug interface present on deliverable hardware, along with the method by which each will be disabled or removed prior to operations, with this documentation submitted as a controlled deliverable. Verification should include physical inspection and functional testing to confirm that interfaces designated for disablement or removal cannot be used and that interfaces retained for authorized purposes are protected as specified. Evaluation criteria should assess offerors' approach to debug interface disablement, their experience designing hardware with reliable physical port disablement capabilities, and their proposed inspection and verification methodology.

Pre-Operations Developer/Supplier

Hardware designers must identify all physical debug, programming, maintenance, and data interfaces during board design and determine whether each interface is required during spacecraft operations. Interfaces not authorized for operational use must have a defined method for disablement, removal, or physical inaccessibility. Physical barriers such as conformal coating or potting should be treated as supplementary protection unless they prevent use of the underlying interface. The disablement approach should reflect whether an interface has an authorized post-integration purpose. Interfaces with no authorized operational or maintenance use should employ irreversible or hardware-enforced disablement where feasible. Interfaces retained for authorized maintenance must remain disabled by default, with reactivation limited to a documented, access-controlled, and approved process. A port disablement plan should be developed as part of the hardware design documentation, listing each physical interface, its function during development, the planned disablement method, and the program milestone at which disablement will be executed and verified. Disablement execution should be treated as a formal process event with documented pre- and post-disablement inspection, providing an auditable record that each interface was addressed before the spacecraft entered environments where unauthorized physical access is a credible threat, such as shared integration facilities or launch sites. Test procedures should verify that disabled interfaces are non-functional after disablement and that disablement has not inadvertently affected adjacent circuitry or legitimate operational interfaces.