AC.L2-3.13.5[a] — System & Communications Protection (Public-Access System Separation)
Domain: System & Communications Protection (SC) | Practice: SC.L2-3.13.5 | Objective ID: 3.13.5[a] | Source: NIST SP 800-171 Rev. 2 / CMMC 2.0 Level 2
Assessment Objective: Publicly accessible system components are identified.
Identify all system components that are publicly accessible (web servers, email gateways, DNS servers, VPN endpoints) and separate them from internal CUI-processing systems.