Configuration Management

Configuration management (CM) for space systems requires automated mechanisms to establish, maintain, validate, and report on the approved baseline configuration of spacecraft and supporting ground systems, ensuring the baseline remains current, complete, and accurate throughout the mission lifecycle. Automated mechanisms should support configuration management by improving the accuracy, currency, and validation of configuration records. Automation does not replace formal change control, engineering review, approval, or other configuration management activities that require human judgment. The approved baseline must be readily accessible to authorized personnel for operational decision-making, anomaly investigation, and change impact assessment. Deviations between the documented baseline and the actual system configuration represent both security and operational risk because undocumented changes may introduce vulnerabilities, mask adversary activity, or produce unpredictable system behavior. Automated validation should identify and report configuration drift at mission-defined intervals or following relevant change events, based on system observability and mission risk.

ID: CM0023
Tier: II
Ground CM 
Created: 2022/10/19
Last Modified: 2026/08/06

Pre-Operations Government

Acquisition requirements should mandate automated support for baseline maintenance, change tracking, configuration validation, and drift detection for spacecraft and ground-system components where technically feasible. Components or configuration attributes that cannot be automatically validated should be identified and managed through documented alternative procedures. Requirements should specify that the configuration baseline be documented at a level of granularity sufficient to detect security-relevant changes, including software versions, firmware versions, hardware component identifiers, network and interface configurations, and security-relevant parameter settings. Contract language should require that the configuration management system be operational and populated with an approved baseline before system acceptance, and that configuration records be delivered to the government as controlled artifacts subject to the program's sensitive information handling requirements. Evaluation criteria should assess offerors' proposed configuration management tooling, their approach to automating baseline validation, and their demonstrated experience implementing configuration management for space or similarly constrained systems. Verification should include demonstration that the automated system correctly detects and reports introduced configuration deviations during acceptance testing.

Pre-Operations Developer/Supplier

Configuration management architecture should be designed as an integrated system capability from the program's outset, with tooling selected for its ability to automatically discover, record, and validate the configuration state of spacecraft hardware, firmware, and software components as well as ground system infrastructure. The configuration baseline should be formally established at each major development milestone, with the baseline at each stage serving as the approved reference against which subsequent changes are tracked and validated. Automated validation mechanisms should be capable of comparing the actual system configuration against the approved baseline on demand and on a scheduled basis, producing reports that clearly identify any discrepancy and classify it by type, location, and potential security or operational significance. Configuration records should be stored in a version-controlled repository with access controls, audit logging, and integrity protection, ensuring that the configuration management system itself cannot be manipulated to conceal unauthorized changes. Integration between the configuration management system and the change management process should ensure that approved changes are reflected in the baseline after implementation and verification. A change should not be considered complete until the deployed configuration and corresponding baseline records have been reconciled.