CA-9 - Internal System Connections

a. Authorize internal connections of [Assignment: organization-defined system components or classes of components] to the system; b. Document, for each internal connection, the interface characteristics, security and privacy requirements, and the nature of the information communicated; c. Terminate internal system connections after [Assignment: organization-defined conditions]; and d. Review [Assignment: organization-defined frequency] the continued need for each internal connection.


ID: CA-9
Enhancements:  1

Space Segment Guidance

Internal connections, payload↔bus, partitions, avionics and payload networks, benefit from early assessment because they are hard to change post-launch. Consider message filtering and labeling, mode-based restrictions that prevent unsafe interactions, parser hardening, and watchdog/partitioning that contain faults. Validate with fault-injection and malformed traffic in twin/flatsat environments and confirm “as-flown” enforcement via telemetry (e.g., filtered message counts, reject codes).