Security Testing Results

Penetration testing, vulnerability scanning, fuzzing, code analysis, adversarial testing, and other security assessment activities are essential for validating the security posture of space systems. However, the artifacts generated by these activities are themselves sensitive mission information requiring protection. Security testing artifacts may include final reports, raw scanner output, working notes, exploit code, proof-of-concept scripts, packet captures, RF recordings, screenshots, logs, memory or core dumps, test credentials, command sequences, telemetry mappings, architecture diagrams, test configurations, remediation records, and copies of software or data collected during testing. Security testing artifacts may reveal exploitable weaknesses, attack paths, security-control gaps, spacecraft and ground-system interfaces, command and telemetry behavior, link characteristics, safety interlocks, test accounts, and system-specific vulnerability conditions. Detailed evidence identifying an exploitable weakness, affected interface, and validated attack method may provide an adversary with much of the information needed to reproduce an attack. Security testing results shall be categorized, marked, handled, stored, transmitted, shared, retained, and disposed of according to their information classification, CUI category, proprietary restrictions, contractual requirements, and mission sensitivity. Protection shall address both unauthorized disclosure and unauthorized modification, because alteration or deletion of test results could conceal vulnerabilities, misrepresent remediation status, or undermine security decisions. Access shall be limited by role and need to know throughout the artifact lifecycle, beginning when the data is generated and continuing through authorized disposition.

ID: CM0008
Tier: I
Ground CM 
Created: 2022/10/19
Last Modified: 2026/08/06

Pre-Operations Government

Acquisition requirements should establish explicit handling, marking, storage, transmission, distribution, retention, and disposition controls for security testing artifacts produced during development, integration, acceptance testing, and other authorized assessment activities. Contract language should identify the process for determining each artifact’s information classification, CUI category, proprietary designation, contractual handling restriction, or other mission-specific sensitivity designation. The requirements should specify the access controls, approved repositories, authorized transmission methods, retention periods, and disposition procedures applicable to each category. Requirements should prohibit storage of security testing results in unauthorized environments and distribution to personnel or systems without an approved role and need to know. Testing artifacts should be retained only for the periods established by contractual, legal, records-management, incident-response, and mission-assurance requirements. Copies no longer required for an authorized purpose should be securely deleted or sanitized in accordance with approved disposition procedures. Testing deliverables should be structured to minimize unnecessary dissemination of exploit details. Executive summaries, risk decisions, and remediation status reports should use finding identifiers and the minimum technical information necessary for their intended audience. Detailed exploit instructions, raw evidence, credentials, command sequences, packet or RF captures, and proof-of-concept code should be maintained in more restricted technical appendices or evidence repositories. Contract deliverable requirements should specify that security testing artifacts be transferred through approved encrypted channels or controlled repositories with required markings, access restrictions, and receipt confirmation. Where artifact integrity or chain of custody is important, the contractor should provide cryptographic hashes, digital signatures, immutable audit records, or equivalent evidence that the material has not been altered. Evaluation criteria should assess offerors’ existing practices for protecting sensitive testing data, controlling third-party access, preserving result integrity, and securely disposing of temporary copies.

Pre-Operations Developer/Supplier

Security testing programs should establish information handling procedures for test results before testing begins, ensuring that output reports, raw scan data, and working notes generated during assessments are controlled from the moment of creation. Access to security testing results should be restricted to personnel directly responsible for remediation and system security oversight, with access lists reviewed and recertified at defined intervals. Security testing artifacts should be stored in access-controlled repositories with audit logging enabled, transmitted only over encrypted channels, and never retained on shared drives, collaboration platforms, or personal devices without equivalent controls. Contractors, consultants, cloud-service providers, tool vendors, and third-party testers that generate, process, store, or receive security testing artifacts should be bound by contractual requirements addressing confidentiality, integrity, permitted use, personnel access, subcontractor access, storage location, breach notification, retention, return, sanitization, and disposition. Testing artifacts should not be used for product development, model training, benchmarking, demonstrations, publications, or other secondary purposes without explicit authorization. Remediation tracking systems that reference specific vulnerability findings should apply the same access controls as the source reports, as tracking records frequently contain sufficient detail to reconstruct exploitable vulnerability information.