Physical Security Controls

Physical security controls form the outermost defensive layer protecting systems that can command the spacecraft, limiting access to commanding infrastructure to personnel who are both identity-verified and specifically authorized to be in those environments. Unauthorized physical access may enable theft, tampering, connection to exposed interfaces, use of unattended sessions, or attempts to extract or alter protected information. Physical security must therefore complement authentication, encryption, session management, tamper protection, and other technical controls rather than assume those controls will remain sufficient without protection of the underlying equipment. Physical security measures for commanding facilities and infrastructure must use layered controls selected according to the facility threat environment, system criticality, site characteristics, and consequence of unauthorized access. Controls may include perimeter barriers, controlled entry points, interior protected areas, identity and authorization verification, locks, intrusion detection, surveillance, and security personnel. Access to the facility must not, by itself, authorize physical access to commanding systems. Physical security controls must be commensurate with the sensitivity and criticality of the commanding functions they protect, with the most sensitive commanding capabilities requiring the most stringent physical access restrictions.

ID: CM0053
Tier: II
Ground CM 
Created: 2022/10/19
Last Modified: 2026/08/06

Pre-Operations Government

Acquisition requirements should mandate physical security controls for all facilities and infrastructure through which spacecraft commanding is conducted, with specifications defining minimum control requirements for each facility category based on the sensitivity of the commanding functions performed therein. Requirements should address the full range of physical security elements, including perimeter security, access control mechanisms, identity verification approaches, security personnel staffing, visitor escort procedures, and physical security monitoring, with the selected combination of controls documented and justified against the facility's threat environment and the criticality of the commanding capability it houses. Contract language should require that physical security plans for commanding facilities be submitted as controlled deliverables for government review and approval, and that any significant change to facility physical security configuration be treated as a change requiring re-review before implementation. Evaluation criteria should assess offerors' existing physical security posture for facilities that will house commanding infrastructure, their experience implementing physical security programs commensurate with the sensitivity of space mission commanding, and their proposed approach to monitoring and auditing physical access. Verification should include physical security inspections of commanding facilities at defined program milestones, confirming that implemented controls meet requirements and that access records are being maintained and reviewed.

Pre-Operations Developer/Supplier

Physical security requirements should be incorporated during facility selection, design, construction, or fit-out so that protected areas, access points, monitoring, cabling protection, and response capabilities can be integrated efficiently. Existing facilities may be used when a documented assessment identifies necessary remediation and confirms that the resulting controls satisfy mission requirements. The layered physical security design should treat the commanding terminal and its immediate environment as the innermost protected zone, with progressively more permissive access controls applied to outer facility zones, ensuring that an individual who gains access to outer areas faces additional barriers before reaching commanding capability. Identity verification for access to commanding areas should use mechanisms that provide individual attribution and are not easily shared or transferred, such as credential-plus-biometric combinations or smartcard-based systems with personal identification number (PIN) authentication, so that access records reflect actual individuals rather than merely credential presentation. Controls should address credential sharing, tailgating, lost credentials, and unauthorized escort practices because an access record alone does not prove that only the authorized individual entered the protected area. Physical access logging, intrusion detection, and surveillance should be applied to mission-defined entry points and protected operational areas to support deterrence, detection, response, and investigation. Surveillance placement, access, retention, and review must comply with applicable legal, privacy, personnel, classification, and information-protection requirements and should avoid unnecessary capture of credentials, sensitive displays, or command content. Physical security procedures should address the full range of access scenarios, including authorized visitor access with escort requirements, maintenance personnel access to commanding infrastructure, and emergency access procedures that maintain security during non-standard situations without creating exploitable exceptions.