SC-7(29) - Boundary Protection | Separate Subnets to Isolate Functions

Implement [Selection: physically; logically] separate subnetworks to isolate the following critical system components and functions: [Assignment: organization-defined critical system components and functions].


ID: SC-7(29)
Enhancement of : SC-7

Space Segment Guidance

Specific missions require the vehicle to open a transient network path, such as downlinking bulk science data through a commercial relay. After the session ends, the interface should close hard, flushing routing tables and session keys so an attacker who observes traffic timing cannot reopen the path later. Implement connection brokers that issue time-bound tokens, embed the expiry in telemetry, and program the firewall to drop all packets once the token lapses. Periodic self-tests verify that dormant interfaces truly reject traffic.