User Training

Human factors represent one of the most consistently exploited attack vectors against space mission systems; adversaries routinely use spear phishing, social engineering, and other user-interaction techniques to gain initial access to mission networks, development environments, and operational infrastructure. User training reduces this attack surface by building personnel awareness of adversary techniques and the behaviors required to recognize and resist them. Training must be role-differentiated: general security awareness training is required for all personnel with access to mission systems, while personnel with assigned security roles and responsibilities require additional role-based training commensurate with the specific duties and access rights they hold. Training must be completed before a user is granted access to mission systems or authorized to perform assigned security duties; updated when system changes introduce new threats, procedures, or access controls that alter the security context in which personnel operate; and refreshed at least annually, or more frequently if the mission's security policy specifies a shorter interval. Training program effectiveness should be measurable, with completion records maintained and knowledge validation incorporated to confirm that training objectives are being achieved rather than simply delivered.

Sources

ID: CM0041
Tier: I
Ground CM 
Created: 2022/10/19
Last Modified: 2026/08/06

Pre-Operations Government

Acquisition requirements should mandate general security awareness training for contractor personnel with access to mission systems, development environments, or mission-sensitive information, and additional role-based training for personnel assigned security-relevant management, operational, or technical responsibilities. Required training must be completed before applicable access or duties are authorized. Requirements should specify the minimum training content for general users and the additional content required for personnel in defined security roles, and should require that training records be maintained and made available for government audit. Contract language should require that training be updated whenever significant system changes, new threat intelligence, or revised security procedures alter the security context in which personnel operate, and that personnel complete updated training before exercising access rights affected by the change. Evaluation criteria should assess offerors' existing security training programs, their approach to role differentiation, and their processes for tracking completion, measuring effectiveness, and updating content in response to evolving threats. Verification should include review of training completion records at defined program milestones, confirming that all personnel with access to mission systems have completed required training appropriate to their role.

Pre-Operations Developer/Supplier

Security training program development should begin before personnel are onboarded to the program, ensuring that training content is available and completion can be verified before access is granted rather than after personnel are already working with mission systems. General awareness training content should address the specific social engineering and spear phishing techniques known to target space industry personnel and organizations, using realistic scenarios drawn from the mission's threat intelligence rather than generic examples that may not resonate with the target audience. Role-based training for personnel in security roles, including system administrators, security engineers, incident responders, and mission operations personnel with elevated access, should address the specific threats, procedures, and technical controls relevant to each role, with content updated as the system and threat environment evolve. Training effectiveness should be assessed using methods appropriate to the training objectives, such as knowledge checks, authorized practical exercises, or skills demonstrations, rather than completion tracking alone. Results should be used to identify training content or personnel requiring additional reinforcement. Training records should be maintained in a system that supports audit, tracks completion against role requirements, and generates alerts when personnel are approaching or have exceeded the required training refresh interval.