Monitor Critical Telemetry Points

Monitoring defined spacecraft telemetry points provides a key source of evidence for detecting adversary activity against on-orbit systems, where observability is largely limited to the events and conditions the spacecraft can sense, record, and report. Monitored telemetry must include both accepted and rejected commands, command mode transitions, command counters, and other indicators of commanding activity, enabling detection of unauthorized command attempts that fail authentication as well as anomalous patterns in legitimate command traffic. Monitoring scope should include RF and link-quality indicators that support detection and triage of interference or suspected jamming. These indicators should be correlated with expected link conditions and other available evidence before hostile activity is concluded. Security-relevant telemetry should be integrated and time-correlated with ground-based defensive cyber operations infrastructure, including security information and event management (SIEM) and audit platforms, to provide unified space-system cybersecurity situational awareness. The resulting view should correlate spacecraft observations with relevant ground-system security events while accounting for telemetry latency, contact availability, and other observability limitations.

ID: CM0034
Tier: I
Onboard SV CM  Ground CM 
Created: 2022/10/19
Last Modified: 2026/08/06

Pre-Operations Government

Acquisition requirements should mandate the definition of a monitored telemetry point list as a program deliverable, specifying the commanding, RF, and operational health telemetry parameters to be collected and evaluated for security-relevant anomalies, with the list derived from the mission's threat model and criticality analysis. Requirements should specify that telemetry designs include both accepted and rejected command records, with sufficient metadata, including timestamps, command identifiers, source indicators, and rejection reason codes, to support security event reconstruction and forensic analysis. Contract language should require that ground system designs include integration between the telemetry processing pipeline and defensive cyber operations infrastructure, such as SIEM platforms, enabling correlated analysis of spacecraft telemetry and ground system security events in a unified operational picture. Evaluation criteria should assess offerors' proposed telemetry monitoring architectures, their experience designing telemetry systems for security monitoring purposes, and their proposed approach to SIEM integration for space system situational awareness. Verification should include demonstration that the monitoring system correctly detects and records both successful and rejected command events and that telemetry data is accessible to the ground-based security monitoring infrastructure in operationally useful timescales.

Pre-Operations Developer/Supplier

Telemetry architecture design must explicitly account for security monitoring requirements alongside operational health and status functions, with security-relevant telemetry points identified during the threat modeling process and included in the telemetry definition before the command and data handling subsystem design is finalized. Command telemetry should be designed to capture sufficient context for each command event, including whether the command was accepted or rejected, the basis for rejection, and any available source or session information, so that the telemetry record supports security analysis rather than providing only functional status. RF monitoring telemetry should include available receiver and link-quality measurements, with sampling, aggregation, and retention sufficient to support detection and triage of interference events within mission resource constraints to support detection of transient interference events that may indicate adversary activity. Ground system architectures should establish automated data pipelines that route security-relevant telemetry to SIEM or equivalent platforms for correlation with ground system audit logs, network security events, and threat intelligence feeds, enabling analysts to view the complete space system security posture rather than spacecraft and ground system events in isolation. Alert thresholds and correlation rules applied to monitored telemetry points should be defined during the design phase, informed by the threat model, and validated through simulation or testbed exercises before operational deployment.