Station Compliance›Field Notes
EAS Security
The third requirement is the one with real money attached, and it is also the one written most loosely on purpose. What the text actually demands is narrower than most stations assume.
By Mark Shannon ·
Of the three things § 11.35(d) requires, two cost nothing but time. The third can cost money, and it is the one stations ask about most.
The text is one sentence:
(3) Use a network firewall or comparable network segmentation practice that limits remote management access to authorized devices and authorized users.
Read the whole sentence, not the first six words. The obligation is not "own a firewall." The obligation is the clause after it — limit remote management access to authorized devices and authorized users — and a firewall is named as one way to get there.
The Commission was explicit that it did not want to prescribe a technology. Its stated view is that firewalls are "widely recognized as a basic and cost-effective cybersecurity safeguard appropriate even for organizations with" limited resources, and that identifying one would not be burdensome or time-consuming. But it wrote in the alternative because network topologies differ, and a rule naming a product would age badly.
The order also grounds the requirement in CISA's Cybersecurity Performance Goals, and in the NIST Cybersecurity Framework element covering protection from unauthorized logical access — where the implementation example is that only necessary communications should be allowed into a network from external networks, which should be logically segmented.
That is the concept the rule is reaching for. Not a box. A boundary.
There is a spectrum here, and stations sit at different points on it already.
The device is not reachable from the internet at all. If your STL, automation and EAS gear live on a LAN with no port-forwarding rules pointing at them and no public IP, you are much closer to compliant than you think. Remote management access is already limited to devices on that network. What you need is to be able to demonstrate that is true — which means the port-forwarding audit, not a purchase.
Remote access exists, through a VPN. A VPN that authenticates users and terminates on the station network is a textbook "comparable network segmentation practice." Access is limited to authorized users, on authorized devices, and the gear itself is never exposed. For most small stations this is the right answer and it is often free — the business router already does it.
A separate VLAN or physically separate switch for broadcast gear. Segmentation in the most literal sense. Effective, and it also solves problems that have nothing to do with the FCC, like the office printer's traffic and the automation system sharing a collision domain.
A firewall appliance with rules limiting management interfaces. The named path. Fine, and appropriate for larger facilities or clusters, but not the only route and rarely the cheapest.
What does not satisfy it: a port-forwarding rule to a device with a good password. The rule asks you to limit access, not to strengthen the thing being accessed. A strong password on a publicly reachable management interface satisfies (d)(1) and does nothing for (d)(3). These are separate requirements and you have to clear both.
If you do one thing on this requirement, do this: log into your router and list every port-forwarding rule and every DMZ host. All of them, not just the ones you believe relate to broadcast.
For each rule, ask a single question: does this expose a device that touches my programming to the open internet? If yes, the rule has to go, and whatever it was accomplishing has to be reached another way — almost always a VPN.
This is unglamorous and it is where the actual exposure lives. Years of "just forward 80 so I can check it from home" accumulate into an inventory nobody has reviewed since it was created, often across more than one person's tenure. In the incidents the FCC cited when it wrote this rule, the entry point was in every case a remotely accessible device that should not have been remotely accessible.
The phrase is doing quiet work. It suggests two axes:
You do not need enterprise identity management to satisfy this. You need to be able to answer "who can reach the transmitter remote control, and from where?" with something more specific than "anyone who knows the URL."
The FCC's own estimate is that patching and password work happen in the normal course of business at little or no additional cost, and that firewalls or segmentation are where stations may actually incur costs. That is a fair read.
But the realistic bill for a one-rack station is lower than the rule sounds:
The expensive version — a consultant designing a segmented network from scratch — is the version stations buy when they do not know which of the above already applies to them. Finding out is free.
There is no filing requirement attached to any part of § 11.35(d), including this one. So the reason to write down what you did is not the FCC. It is that "comparable network segmentation practice" is a judgement call, and the person who made the judgement will eventually leave.
Record what the topology is, which devices are reachable from where, what you removed, and why the remaining path is limited. One page. It is the difference between a station that can answer a question in five minutes and one that has to rediscover its own network.
The equipment guide covers which devices fall inside the scope of the rule, and the rule reference covers all three requirements together.
Everything on this site is free to read. The Program Chain Compliance Kit is the implementation version — the device-by-device reference, the network patterns for a one-rack station, and the worksheets that leave a paper trail behind the work.
The rules on this site change without warning — a deadline gets waived, a filing window opens, a Public Notice lands on a Friday. Leave an address and you get an email when something changes that affects a small station. Nothing else, and one click to leave.