System and Communications Protection
15 controls
Boundary Protection
The SL5 Network encompasses SL5 model development, training, and deployment operations. External network connections are prohibited to prevent unauthorized access and exfiltration while supporting SL5 activities. The...
View detailsPrevent Exfiltration
Organizations prevent exfiltration of covered models through physical bandwidth limitation on outbound flows from Weight Enclaves. Hardware-enforced rate limiting provides deterministic throughput caps that prevent...
View detailsIsolation of System Components
Weight Enclaves isolate systems requiring direct access to covered models within the SL5 Network. This isolation protects against weight exfiltration while enabling operations such as training, inference, fine-tuning,...
View detailsTransmission Confidentiality and Integrity
Cryptographic Protection
Accelerator Interconnect Encryption: AI accelerators within Weight Enclaves cryptographically protect all data transmitted over chip-to-chip interconnects (e.g., NVLink, UALink, custom fabrics). Hardware-level...
View detailsProtected Distribution System
All Weight Enclave network traffic leaving the Red Zone perimeter requires PDS per CNSSI 7003. Unlike standard SCIF requirements (which apply only to unencrypted traffic), SL5 requires PDS for all Weight Enclave...
View detailsCryptographic Key Establishment and Management
Cryptographic Protection
This standard requires post-quantum (quantum-resistant) cryptographic algorithms for inline network encryptors at inter-facility boundaries per SC-8(1); the specific algorithms are selected in accordance with current...
View detailsCollaborative Computing Devices and Applications
Disabling and Removal in Secure Work Areas
No wireless devices or collaborative computing devices (cameras, microphones, video conferencing) are permitted in Red Zones. All equipment must be hardwired with wireless capabilities physically removed or disabled.
View detailsProtection of Information at Rest
Cryptographic Keys
AI accelerators within Weight Enclaves provide a dedicated secure element for cryptographic keys used in encrypted data paths and attestation. The host system cannot access this key storage. Hardware-provisioned...
View detailsHeterogeneity
The organization deploys at least two inline network encryptors from different suppliers in series for each inter-facility connection, consistent with the NSA “Rule of Two” [11]. Different suppliers means different...
View detailsSystem Partitioning
Weight Enclaves constitute separate physical and logical domains within the SL5 Network. This partitioning protects covered models from unauthorized access by other SL5 Network components while enabling interactions...
View detailsHardware-Enforced Separation and Policy Enforcement
AI accelerators within Weight Enclaves implement hardware-enforced separation establishing the accelerator as an independent security domain from the host. The accelerator prevents memory access from the host to...
View details