PM-17 - Protecting Controlled Unclassified Information on External Systems

a. Establish policy and procedures to ensure that requirements for the protection of controlled unclassified information that is processed, stored or transmitted on external systems, are implemented in accordance with applicable laws, executive orders, directives, policies, regulations, and standards; and b. Review and update the policy and procedures [Assignment: organization-defined frequency].


ID: PM-17
Enhancements: 

Space Segment Guidance

Protecting Controlled Unclassified Information (CUI) on external systems is a nontrivial challenge, given the intricacies of international launch collaborations, commercial payload hosting, and multi-organization ground test facilities. Strategies include contractual mandates that external partners implement equivalent cybersecurity protections—such as end-to-end encryption for data transfers and multi-factor authentication for accessing test results. Further, it is critical to classify precisely which data elements qualify as CUI and ensure that any shared storage environment uses robust separation (e.g., containerization or sandboxing) to block cross-tenant data leaks. Monitoring solutions aligned with organizational risk tolerance can continuously verify that third-party handling aligns with the CUI-handling requirements. If discrepancies arise, rapid escalation and remediation processes help minimize exposure and maintain trust among all parties contributing to the spacecraft mission.