CM-7(2) - Least Functionality | Prevent Program Execution

Prevent program execution in accordance with [Selection (one or more): [Assignment: organization-defined policies, rules of behavior, and/or access agreements regarding software program usage and restrictions] ; rules authorizing the terms and conditions of software program usage].


ID: CM-7(2)
Enhancement of : CM-7

Space Segment Guidance

Mode-aware functionality can reduce risk while preserving operability. Consider ensuring nonessential capabilities are available only in defined modes (e.g., maintenance), that transitions in/out of those modes clean up elevated privileges, and that safe/contingency modes narrow the active surface by default. Telemetry that explicitly reports which capabilities are enabled/disabled after resets or SEUs helps validate least-functionality assumptions during short passes.