AC-20(3) - Use of External Systems | Non-organizationally Owned Systems , Restricted Use
Restrict the use of non-organizationally owned systems or system components to process, store, or transmit organizational information using [Assignment: organization-defined restrictions].
When connecting systems of differing assurance (e.g., academic partners, research networks), consider a mediation layer that constrains directionality, validates formats, sanitizes content, and rate-limits transfers. TT&C injection should remain off-limits from lower-assurance domains; for science or planning data that must cross, provenance and quarantine workflows help trace and contain issues without disrupting flight operations.
Exploit ground system and use to maliciously to interact with the spacecraft
Sample Requirements
SPARTA ID
Requirement
Rationale/Additional Guidance/Notes
SPR-285
The [organization] risk assessment shall include the full end to end communication pathway (i.e., round trip) to include any crosslink communications.{SV-MA-4}{AC-20,AC-20(1),AC-20(3),RA-3,SA-8(18)}
Full pathway analysis prevents overlooking intermediate segments. Crosslinks may introduce lateral risk exposure. Round-trip evaluation strengthens confidentiality and integrity assurance. Holistic view reduces blind spots.
SPR-411
The [organization] shall define and enforce restrictions on activities and transactions permissible when interacting with external systems.These access controls shall be regularly reviewed and updated to align with organizational security policies and requirements.{SV-AC-1,SV-MA-7}{AC-20,AC-20(1),AC-20(3)}
External systems may introduce compromise pathways. Defined boundaries limit exposure. Regular review ensures alignment with evolving policy. Controlled interfaces strengthen resilience.