AC.L2-3.13.5[b] — System & Communications Protection (Public-Access System Separation)
Domain: System & Communications Protection (SC) | Practice: SC.L2-3.13.5 | Objective ID: 3.13.5[b] | Source: NIST SP 800-171 Rev. 2 / CMMC 2.0 Level 2
Assessment Objective: Subnetworks that are publicly accessible are physically or logically separated from internal networks.
Place publicly accessible components in DMZs or separate network segments with firewall controls that prevent direct access to internal CUI systems from the public-facing zone.