Protect Sensitive Information

Space mission sensitive information spans a broad attack surface and must be inventoried, classified, and protected at a level commensurate with its sensitivity across every location where it resides, including ground systems, contractor networks, and remote access environments. Sensitive material typically includes functional and performance specifications, interface control documents (ICDs), command and telemetry (C&T) databases, uplink protection schemes including disable and bypass features, fault management logic, scripts, simulation and rehearsal results, failure and anomaly resolution records, and architecture and software documentation. Each information type must be assigned a protection level, such as unclassified, controlled, proprietary, or classified, and access must be restricted to personnel with defined roles and a verified need to know. Sensitive data shall be protected at rest and in transit using encryption or other mission-approved safeguards commensurate with its classification, sensitivity, threat exposure, and operational constraints. DLP capabilities shall be applied to systems and data flows where they are technically feasible and effective, with alternative access controls, monitoring, or information-flow protections used where conventional DLP technology is not suitable. Ongoing configuration management must track, control, and document all changes to command procedures and critical database content to prevent unauthorized modification and mission degradation.

ID: CM0001
Tier: I
Ground CM 
Created: 2022/10/19
Last Modified: 2026/08/06

Pre-Operations Government

Acquisition documents should explicitly enumerate categories of sensitive mission information, including C&T databases, ICDs, and fault management documentation, and require contractors to submit formalized plans identifying how each category is classified, stored, and controlled. Contract language should flow information protection requirements to all tiers of the supply chain, requiring that any contractor handling controlled or sensitive mission information comply with the same protection standards applied to the prime contractor. Evaluation criteria should assess contractor DLP tool selection, encryption implementation, and role-based access control (RBAC) architecture for adequacy relative to the sensitivity of the information categories involved. Verification should include government review of contractor information protection artifacts at milestone reviews and contractually required independent assessments prior to system delivery or operational handoff.

Pre-Operations Developer/Supplier

During architecture and design, mission developers must conduct a structured data classification exercise, cataloging all sensitive information types, assigning protection levels, and mapping them to specific storage systems, transmission paths, and user roles before detailed design begins. Access control architecture should implement RBAC with least-privilege enforcement, integrated with identity management solutions where multi-organization access is required. Encryption must be applied at rest and in transit across all ground system components and contractor networks, using widely accepted and validated cryptographic mechanisms suited to the sensitivity of the protected data. DLP tooling should be selected and configured during development rather than post-deployment, with policy rules tailored to mission-specific data types such as binary command files, telemetry schemas, and ICD formats. Configuration management tooling with audit logging must be integrated into the development workflow so that sensitive configuration artifacts are tracked from initial baseline establishment forward.