CM-7(9) - Least Functionality | Prohibiting The Use of Unauthorized Hardware

(a) Identify [Assignment: organization-defined hardware components authorized for system use]; (b) Prohibit the use or connection of unauthorized hardware components; (c) Review and update the list of authorized hardware components [Assignment: organization-defined frequency].


ID: CM-7(9)
Enhancement of : CM-7

Space Segment Guidance

Interfaces not needed on-orbit, unused serial ports, JTAG, telnet/SSH services, or test antennas, can be disabled or physically inhibited before launch. Consider documenting any retained contingency interfaces, how they authenticate, and how enable/disable states are verified during I&T and after software updates. Apply similar discipline on the ground by closing unused services on modulation chains and control hosts, and by re-validating after maintenance.