Two-Person Rule

The two-person rule (TPR) requires that all access to and actions within systems possessing command-level authority over the spacecraft be conducted in the continuous presence of two separately authorized individuals, neither of whom alone can complete the access or action. This control reduces the opportunity for unauthorized, coerced, erroneous, or malicious commanding by requiring two independently authorized individuals to participate in the protected access or action. Its effectiveness depends on individual attribution, independent review, resistance to credential sharing or account misuse, and protection against collusion or bypass of the enforcement mechanism. The TPR requires two distinct, appropriately authorized individuals to participate in the same protected access or action. Participation may be physically co-located, remotely performed through authenticated technical controls, or implemented through a combination of physical and logical mechanisms, as defined by mission policy. The second individual must independently review and approve the specific access or action before it is completed. Under CM0054, the two-person rule applies to access and actions involving systems with command-level access to the spacecraft to include reprograming the flight computer/flight software. If the mission tailors the rule to selected commanding functions, the retained scope, excluded access and actions, compensating controls, and associated risk acceptance must be explicitly documented and approved.

ID: CM0054
Tier: I
Ground CM 
Created: 2022/10/19
Last Modified: 2026/08/06

Pre-Operations Government

Acquisition requirements should mandate the two-person rule for access and actions involving systems with command-level access to the spacecraft. Any program-approved tailoring that limits the rule to specified commanding functions must document the selection criteria, exclusions, compensating controls, and approving risk authority, with the specific functions subject to TPR identified and documented in the system security requirements before the commanding architecture is designed. Requirements should specify technical enforcement of dual authorization for protected digital access and commanding actions where supported, requiring approval by two distinct authenticated individuals before the action can be completed. Procedural or physical controls may supplement technical enforcement or address activities that cannot be directly system-enforced, but must provide equivalent individual accountability and independent participation. Contract language should require that TPR procedures be documented in operational concept documents, that the technical implementation of TPR controls be verified through testing that confirms no single authorized individual can complete a TPR-protected action without the concurrent authenticated participation of a second authorized individual, and that any proposed deviation from TPR for a protected function be approved at a defined authority level. Evaluation criteria should assess offerors' proposed TPR architecture, their experience implementing technically enforced dual-authorization for space commanding functions, and their approach to maintaining TPR compliance during contingency operations when staffing may be reduced. Verification should include adversarial testing that attempts to complete TPR-protected commanding actions through single-person means, confirming that all such attempts are blocked by both technical and procedural controls.

Pre-Operations Developer/Supplier

Two-person rule implementation should be designed with technical enforcement as the primary mechanism and procedural controls as a complementary layer, recognizing that procedures alone are susceptible to circumvention under operational pressure, coercion, or adversarial manipulation. The commanding architecture must require approvals from two distinct, individually authenticated and appropriately authorized people before a TPR-protected command or action can be completed. Both approvals must be bound to the exact command, parameters, target, operational context, and validity period being approved. Modification of the approved action must invalidate prior approvals, and unused approvals must expire after a mission-defined period. The authentication mechanism for each of the two required individuals must be individually attributed and non-transferable, using distinct credentials that cannot be shared, delegated, or satisfied by a single person using multiple accounts or credentials. Operational procedures must define whether physical co-presence, authenticated remote participation, or another approved dual-authorization arrangement is required for each protected activity. Regardless of location, the second individual must actively review the specific action and possess the authority, information, and technical capability necessary to approve or reject it. Physical co-presence must be required where mission risk or applicable policy determines that remote participation does not provide sufficient assurance. Contingency planning must address how TPR-protected actions will be performed when normal staffing, communications, or authorization services are unavailable. The preferred response is to provide alternate authorized personnel or an alternate dual-authorization mechanism. Any emergency single-person exception must be predefined, limited to specifically authorized safety- or mission-preservation actions, time-bounded, fully logged, approved by the designated risk authority where circumstances permit, and reviewed immediately afterward.