AC-20(3) - Use of External Systems | Non-organizationally Owned Systems , Restricted Use

Restrict the use of non-organizationally owned systems or system components to process, store, or transmit organizational information using [Assignment: organization-defined restrictions].


ID: AC-20(3)
Enhancement of : AC-20

Space Segment Guidance

When connecting systems of differing assurance (e.g., academic partners, research networks), consider a mediation layer that constrains directionality, validates formats, sanitizes content, and rate-limits transfers. TT&C injection should remain off-limits from lower-assurance domains; for science or planning data that must cross, provenance and quarantine workflows help trace and contain issues without disrupting flight operations.