# UFS 4-010-06: Cybersecurity of Facility-Related Control Systems
UFS 4-010-06 is a supplemental guidance document, not an enforceable standard. [UFS 4-010-06 Foreword] It provides non-mandatory procedural guidance, best practices, lessons learned, examples, and explanatory materials to help users understand and apply UFC (Unified Facilities Criteria) requirements. [UFS 4-010-06 Foreword] UFS does not create new requirements or modify UFC content.
The document addresses cybersecurity of Facility-Related Control Systems (FRCS) by establishing a framework for determining FRCS impact on missions. [UFS 4-010-06 4-2.2.2.2] Key considerations include whether the mission depends on equipment controlled by the FRCS and the relationship between the FRCS, underlying equipment, and the mission itself. [UFS 4-010-06 4-2.2.2.2] For critical FRCS systems, mitigation options include adding manual controls, using local front ends or display panels, and employing redundant equipment with independent control systems. [UFS 4-010-06 4-2.2.3]
The enforceable cybersecurity requirement for facility-related control systems is established by UFC 4
Unofficial — answered from indexed publication text, which may be incomplete or out of date. Your MAJCOM/unit supplement may be stricter. Verify the official PDF before acting or writing a finding.
No departmental passage retrieved.
No supplement passage retrieved — check the supplement chain on the pub page before citing.
DoDI 4715.28 (effective/current as of 2024-12-17)ded DoD Instruction 4715.22, “Environmental Management Policy for Contingency Locations,” February 18, 2016, as amended Office of the Chairman of the Joint Chiefs of Staff, “DoD Dictionary of Military and Associated Terms,” current edition Secretary of Defense Memorandum, “Mission Focus of the Department of Defense,” March 17, 2025 Unified Facilities Criteria 4-010-06, “Cybersecurity of Facility-Related Control Systems,” September 16, 2016 United States Code, Title 10