Group every CBS in scope into security zones with defined policies and capabilities, each either air-gapped or connected only through means that control the data crossing (for example firewalls, routers, one-way serial links, data diodes or dry contacts), with only explicitly allowed traffic crossing a boundary. All CBSs and networks in a zone meet this UR and E27; zone networks are logically or physically separated from others; CBSs with required safety functions sit in their own physically separated zones; navigation and communication systems are kept apart from machinery or cargo systems (systems approved to an equivalent standard in a dedicated zone); wireless devices have their own zones; untrusted systems are physically separated unless they meet the zone's requirements; and a zone can be isolated without losing the primary functions of its CBSs.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.