HomeControl Library › 3.13.5
3.13 System & Communications Protection5 ptsAlso Level 1

3.13.5 — Wall off your public-facing systems

Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.

Put anything the public can reach — web servers, mail relays, guest Wi-Fi — on a separated subnetwork, not your internal network.

What it actually means

Publicly accessible components — a public web server, a guest network, a mail gateway — must sit in a separate subnetwork, a DMZ, that is physically or logically isolated from the internal network where CUI lives. If a public box gets compromised, the attacker lands in the DMZ, not next to your CUI.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

Also a Level 1 (FCI) requirement and a 5-point control. If you host nothing publicly accessible, document that — but guest Wi-Fi and any internet-reachable service still count.

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library