CM-7(8) - Least Functionality | Binary or Machine Executable Code

(a) Prohibit the use of binary or machine-executable code from sources with limited or no warranty or without the provision of source code; and (b) Allow exceptions only for compelling mission or operational requirements and with the approval of the authorizing official.


ID: CM-7(8)
Enhancement of : CM-7

Space Segment Guidance

Preventing unauthorized code execution benefits from provenance and containment. Consider verifying script/package origin, checking hashes prior to load, constraining interpreters and macros to sandboxed contexts, and binding execution to explicit references in signed packages. Where watchdogs and partitioning exist, ensure they contain faults from experimental payload apps without impacting bus control, and that recovery leaves a clear audit trail.