SC-7(5) - Boundary Protection | Deny by Default , Allow by Exception

Deny network communications traffic by default and allow network communications traffic by exception [Selection (one or more): at managed interfaces; for [Assignment: organization-defined systems] ].


ID: SC-7(5)
Enhancement of : SC-7

Space Segment Guidance

A default-deny posture is well suited to command and management paths. Consider allowing only approved ports/protocols, station IDs, modulation/codec profiles, and message types, with explicit, time/mode-bounded exceptions for maintenance. On-board, accept only command families valid for the current spacecraft state by default, reject others with explicit reason codes, and record outcomes for later analysis across intermittent contacts.