Backdoor Commands

All commands capable of being executed on the spacecraft must be known, documented, and accounted for by the mission and spacecraft owner; the existence of undisclosed or undocumented commands, whether introduced by developers, component suppliers, or subsystem vendors, represents an unacceptable and unmanageable risk to mission integrity. Commands capable of adversely affecting mission success if misused must be identified through deliberate analysis and protected by mission-defined authorization and execution controls commensurate with their consequences. Commands that bypass normal operational safeguards require additional justification and restrictions appropriate to their emergency or contingency purpose. Backdoor, residual, hardware-level, test, diagnostic, or override commands that bypass normal operational pathways or safeguards should be retained only where mission-approved emergency or contingency access requires them. Their inclusion must be explicitly justified, and their commanding authority must be appropriately restricted. Hazardous commands required for normal mission operations are not prohibited by this countermeasure but must be governed by approved authorization, prerequisite, sequencing, and safety controls. Any command capability introduced by a subsystem supplier or component vendor that was not explicitly requested or authorized by the mission owner must be identified, evaluated, and either removed or brought under formal mission command governance before launch.

ID: CM0043
Tier: I
Onboard SV CM 
Created: 2022/10/19
Last Modified: 2026/08/06

Pre-Operations Government

Acquisition requirements should mandate that contractors deliver a complete, authoritative command inventory or dictionary covering every externally invocable or mission-usable command capability resident in delivered flight software, firmware, and hardware. The inventory must include vendor-supplied subsystem commands, hardware commands, test and diagnostic commands, and emergency or override capabilities, with no undisclosed command pathways permitted. Requirements should require that contractors perform a formal analysis of all commands that could adversely affect mission success if executed maliciously or without authorization, with the analysis submitted as a controlled deliverable and reviewed by government technical authorities. Contract language should prohibit the inclusion of undocumented or non-mission-sanctioned command capabilities in deliverable hardware and software, and should flow this prohibition to all subcontractors and component suppliers, requiring them to disclose and document any command capability resident in their delivered items. Evaluation criteria should assess offerors' command governance processes, their approach to identifying and controlling supplier-introduced command capabilities, and their proposed verification methodology for confirming command inventory completeness. Verification should include independent analysis of delivered software, firmware, hardware interfaces, and command-processing logic to provide evidence that the command inventory is complete and to identify undocumented or unauthorized command pathways.

Pre-Operations Developer/Supplier

Command inventory completeness must be treated as a security engineering deliverable, not only a functional documentation task, with the command dictionary developed through a process that actively searches for undisclosed command pathways rather than relying solely on developer self-reporting. Subsystem and component suppliers must be contractually required to disclose all command interfaces resident in their delivered hardware and firmware, including factory test commands, diagnostic interfaces, and any capability not part of the mission's operational command set, with disclosure made before delivery and verified through independent analysis of the delivered items. Critical commands providing emergency or override access must have authorization and execution-condition checks enforced by a trusted command-processing mechanism that cannot be bypassed by the command source. The mechanism must restrict execution to authorized commanding entities and approved operational conditions. The command authorization policy for critical commands should define not only who may send them but under what operational conditions they are valid, so that a critical command sent outside its authorized context is rejected regardless of whether the sender's credentials are valid. Command inventory verification should use methods appropriate to the implementation, including review of command-processing logic and interfaces and applicable static, binary, dynamic, or protocol testing, to identify command capabilities not represented in the approved inventory.