CM-7(1) - Least Functionality | Periodic Review

(a) Review the system [Assignment: organization-defined frequency] to identify unnecessary and/or nonsecure functions, ports, protocols, software, and services; and (b) Disable or remove [Assignment: organization-defined functions, ports, protocols, software, and services within the system deemed to be unnecessary and/or nonsecure].


ID: CM-7(1)
Enhancement of : CM-7

Space Segment Guidance

Periodically scanning for and removing “dead weight” functionality in space systems minimizes the risk of an adversary exploiting unnecessary services. Idle network protocols or debugging stubs on a satellite are prime attack vectors, especially during ground integration or servicing. With this enhancement, spacecraft operators inventory all running processes, ports, and APIs to verify each is mission-essential. Anything unnecessary, like legacy file-transfer services, gets disabled or stripped. This tightens the overall attack surface, reducing the likelihood of malicious code slipping in via overlooked features. In turn, the platform gains resilience without excessive complexity.