This control requires organizations to isolate public-facing systems (such as web servers, email gateways, or DNS servers) from internal networks that store or transmit Controlled Unclassified Information (CUI). This is typically done using DMZs (demilitarized zones) or network segmentation.
Read the full blog breakdown of 3.13.5