This objective requires organizations to technically enforce and document which systems are authorized to connect to those that handle Controlled Unclassified Information (CUI). The focus is on ensuring that only approved connections are allowed, and that enforcement is visible in system and network configurations.