Assessment and authorization (A&A) is a structured, formal process through which an organization evaluates the extent to which a system's design and implementation satisfy a defined set of security requirements, and grants or denies authorization for that system to operate based on the assessed risk. For space mission systems, A&A may apply to spacecraft, ground systems, mission networks, supporting infrastructure, common controls, and the interfaces and dependencies among them. The authorization scope and boundary must be defined by the governing risk management framework, mission architecture, information types, applicable requirements, and organizational risk decisions. The assessment phase produces evidence concerning whether selected controls are implemented correctly, operating as intended, and producing the required security outcomes. The resulting authorization package should contain the system security plan, assessment reports, plan of action and milestones, executive risk summary, and other evidence required by the authorizing authority. The authorization decision, made by a designated authority with accountability for accepting the residual risk of operating the system, formally records the organization's acceptance of that risk and establishes the conditions under which the system may operate. Authorization must be supported throughout the system lifecycle by continuous monitoring, security impact analysis, updated risk information, and maintenance of the authorization evidence. Proposed system changes must be assessed before implementation when they could affect the authorization boundary, control implementation, or accepted risk. Significant changes or material deviations from the authorization basis must be reported to the authorizing authority, who determines whether additional assessment, modified authorization conditions, or reauthorization is required.
ID: CM0089
Tier: III
Ground CM
Created: 2023/11/29
Last Modified: 2026/08/06
Pre-Operations Government
Acquisition requirements should establish authorization as a required operational milestone for systems, services, and common controls subject to the applicable assessment and authorization framework. Operational use must remain within the scope, conditions, and limitations approved by the designated authorizing authority, except where a separately approved limited, interim, test, or emergency authorization applies. The authorization package must demonstrate that applicable security requirements have been implemented and assessed for the mission’s classification, operational context, risk tolerance, and authorized use.
Requirements should define the authorization boundary, system categorization, applicable security control baseline and tailoring, inherited or shared controls, external dependencies and interconnections, assessment methodology, required evidence, and authorization-package deliverables. Spacecraft, ground systems, mission networks, and supporting services may be covered by separate authorization decisions, but their interfaces, shared dependencies, inherited controls, and mission-level integration risks must be assessed collectively, with responsibility for each control and risk clearly assigned.
Contract language should require contractors to develop and maintain authorization evidence throughout the system lifecycle and submit interim assessment artifacts at defined program milestones. This approach should enable government technical and security authorities to identify control deficiencies, evidence gaps, and unresolved risks while corrective action remains practical and cost-effective rather than deferring authorization activities until system delivery.
Evaluation criteria should assess each offeror’s experience supporting the applicable authorization process, proposed security assessment methodology, approach to producing and maintaining authorization evidence, and demonstrated ability to support the authorization of systems with comparable security, mission, and operational requirements.
Verification should include government review of authorization artifacts at defined milestones and a security control assessment completed before the authorization decision. Assessors must possess sufficient independence and objectivity from the system’s development and operation, with the required level of independence determined by the system’s risk, criticality, and applicable authorization framework.
Pre-Operations Developer/Supplier
Organizations subject to a formal A&A requirement should establish the applicable authorization framework during program planning. This includes identifying the authorizing authority, authorization boundary, security control baseline and tailoring, inherited controls, assessment methodology, required evidence, and authorization-package structure early enough to inform security engineering and evidence collection. The authorization package structure should be defined early, as the evidence required to demonstrate control compliance, including design documentation, test results, configuration records, and risk assessment artifacts, must be planned for and collected throughout development; attempting to reconstruct this evidence after the fact is significantly more costly and often incomplete. For commercial missions subject to government authorization requirements, early and ongoing engagement with the authorizing authority is essential to ensure that the security control baseline, assessment methodology, and package format meet the government's expectations before the program has invested significant effort in a direction that may require rework. Ongoing authorization should be evaluated where permitted by the applicable A&A framework and supported by a mature continuous monitoring program. Continuous monitoring and ongoing assessment provide current risk information to the authorizing authority but do not independently authorize system changes or eliminate the need for an accountable authorization decision. The organization must define the controls and risks to be monitored, assessment frequencies, change thresholds, reporting requirements, and conditions requiring formal reassessment or a new authorization decision. The authorization boundary must be clearly defined and documented, specifying which systems, interfaces, and external services are within the authorization scope and which are covered by separate authorization actions, as an unclear boundary can leave significant security risks unassessed.
Sustainment & Maintenance Government
Operational authorization maintenance requires an active continuous monitoring program that tracks the status of security controls, collects security-relevant performance data, and assesses whether changes to the system or its environment have introduced risks not addressed by the current authorization. Any change to the system's software, hardware, configuration, or operational environment that affects the security control implementation or effectiveness documented in the authorization package should be evaluated against the authorization's conditions of operation, with changes that exceed defined thresholds triggering a formal reassessment process. Authorization package documentation must be maintained as living records updated to reflect the system's current security posture, ensuring that the authorization basis remains accurate and that the authorizing authority has a current and truthful picture of the system's risk profile. Security findings identified through continuous monitoring and assessment activities must be documented, risk-assessed, assigned to accountable owners, and tracked through remediation, mitigation, or approved risk acceptance. Findings that materially alter the authorized risk, exceed approved remediation or risk-acceptance conditions, or indicate significant control failure must be reported to the authorizing authority for a decision to maintain, modify, suspend, or withdraw the authorization or require corrective action.
Sustainment & Maintenance Developer/Supplier
Operational authorization maintenance requires an active continuous monitoring program that tracks the status of security controls, collects security-relevant performance data, and assesses whether changes to the system or its environment have introduced risks not addressed by the current authorization. Any change to the system's software, hardware, configuration, or operational environment that affects the security control implementation or effectiveness documented in the authorization package should be evaluated against the authorization's conditions of operation, with changes that exceed defined thresholds triggering a formal reassessment process. Authorization package documentation must be maintained as living records updated to reflect the system's current security posture, ensuring that the authorization basis remains accurate and that the authorizing authority has a current and truthful picture of the system's risk profile. Security findings identified through continuous monitoring and assessment activities must be documented, risk-assessed, assigned to accountable owners, and tracked through remediation, mitigation, or approved risk acceptance. Findings that materially alter the authorized risk, exceed approved remediation or risk-acceptance conditions, or indicate significant control failure must be reported to the authorizing authority for a decision to maintain, modify, suspend, or withdraw the authorization or require corrective action.
The verifiable process should also include a cross reference to mission objectives and impact statements. Understanding the flaws discovered and how they correlate to mission objectives will aid in prioritization.
SPR-250
The [organization] shall verify that the scope of security testing/evaluation provides complete coverage of required security controls (to include abuse cases and penetration testing) at the depth of testing defined in the test documents.{SV-SP-1,SV-SP-2,SV-SP-3,SV-SP-6,SV-SP-7,SV-SP-9,SV-SP-11}{CA-2,CA-8,RA-5(3),SA-11(5),SA-11(7)}
* The frequency of testing should be driven by Program completion events and updates.
* Examples of approaches are static analyses, dynamic analyses, binary analysis, or a hybrid of the three approaches
SPR-251
The [organization] shall maintain evidence of the execution of the security assessment plan and the results of the security testing/evaluation.{SV-SP-1,SV-SP-6,SV-SP-7,SV-SP-9,SV-SP-11}{CA-2,CA-8,SA-11}
Documented evidence provides traceability and accountability for security testing activities. Without retained artifacts, organizations cannot demonstrate due diligence or validate corrective actions. Preserved results support audits, mission reviews, and lessons learned. This strengthens governance and compliance posture.
SPR-252
The [organization] shall create and implement a security assessment plan that includes: (1) The types of analyses, testing, evaluation, and reviews of all software and firmware components; (2) The degree of rigor to be applied to include abuse cases and/or penetration testing; and (3) The types of artifacts produced during those processes.{SV-SP-1,SV-SP-2,SV-SP-3,SV-SP-6,SV-SP-7,SV-SP-9,SV-SP-11}{CA-2,CA-8,SA-11,SA-11(5)}
The security assessment plan should include evaluation of mission objectives in relation to the security of the mission. Assessments should not only be control based but also functional based to ensure mission is resilient against failures of controls.
Independent assessment reduces bias and uncovers blind spots in internal reviews. External testers provide objective validation of system resilience. Independent penetration testing strengthens confidence in defensive posture. Separation of duties enhances credibility and assurance.
SPR-266
The [organization] shall determine the vulnerabilities/weaknesses that require remediation, and coordinate the timeline for that remediation, in accordance with the analysis of the vulnerability scan report, the mission assessment of risk, and mission needs.{SV-SP-1,SV-SP-2,SV-SP-3,SV-SP-6,SV-SP-7,SV-SP-9,SV-SP-11}{CA-5,CM-3,RA-5,RA-7,SI-3,SI-3(10)}
Not all vulnerabilities carry equal mission impact. Risk-informed prioritization ensures critical flaws are addressed first. Coordinated timelines balance mission needs with security posture. Structured remediation strengthens governance.
SPR-277
In coordination with [organization], the [organization] shall prioritize and remediate flaws identified during security testing/evaluation.{SV-SP-1,SV-SP-3}{CA-2,CA-5,SA-11,SI-3,SI-3(10)}
Timely remediation reduces exploitation window. Coordination ensures mission continuity during patching. Documented prioritization demonstrates due diligence. Structured response enhances accountability.
SPR-282
The [organization] shall use all-source intelligence analysis of suppliers and potential suppliers of the information system, system components, or system services to inform engineering, acquisition, and risk management decisions.{SV-SP-3,SV-SP-4,SV-AV-7,SV-SP-11}{PM-16,PM-30,RA-2,RA-3(1),RA-3(2),RA-7,SA-9,SA-12(8),SR-5(2)}
* The Program should also consider sub suppliers and potential sub suppliers.
* All-source intelligence of suppliers that the organization may use includes: (1) Defense Intelligence Agency (DIA) Threat Assessment Center (TAC), the enterprise focal point for supplier threat assessments for the DOD acquisition community risks; (2) Other U.S. Government resources including: (a) Government Industry Data Exchange Program (GIDEP) – Database where government and industry can record issues with suppliers, including counterfeits; and (b) System for Award Management (SAM) – Database of companies that are barred from doing business with the US Government.
SPR-286
The [organization] shall conduct an assessment of risk prior to each milestone review [SRR\PDR\CDR], including the likelihood and magnitude of harm, from the unauthorized access, use, disclosure, disruption, modification, or destruction of the platform and the information it processes, stores, or transmits.{SV-MA-4}{RA-2,RA-3,SA-8(25)}
Major design decisions must reflect updated threat posture. Pre-milestone risk review prevents costly redesign. Structured evaluation supports informed governance. Early risk integration enhances mission confidence.
SPR-376
The [organization] shall implement an A&A process that establishes the extent to which a particular design and implementation meet a set of specified security requirements defined by the organization, government guidelines, and federal mandates.{SV-MA-6,SV-DCO-1}{CA-2}
Structured authorization ensures design compliance prior to deployment. Formal assessment reduces oversight gaps. Defined requirements provide measurable criteria. Governance supports mission confidence.
SPR-377
The [organization] shall conduct control assessments of the information system using independent assessors.{SV-DCO-1}{CA-2(1)}
Independent assessors shall be individuals or entities external to the operational chain of command and not involved in the development, implementation, or operations of the system under assessment.
SPR-378
The [organization] shall establish and maintain processes to manage and oversee independent assessors, including their qualifications, roles, and responsibilities.{SV-DCO-1}{CA-2(1),CA-7(1)}
Independent assessors shall be individuals or entities external to the operational chain of command and not involved in the development, implementation, or operations of the system under assessment.
SPR-379
The [organization] shall conduct specialized assessments that are specifically tailored for space systems or space missions more generally, as opposed to traditional terrestrial IT systems.{SV-MA-6}{CA-2(2)}
Space missions require threat models distinct from terrestrial IT. Tailored assessments address unique operational constraints. Specialized evaluation improves relevance. Mission-specific review strengthens assurance.
SPR-380
The [organization] shall maintain an up-to-date Plan of Action and Milestones (POA&M) that identifies, assesses, prioritizes, and documents specific actions to be taken to correct deficiencies in the spacecraft's security posture.{SV-DCO-1}{CA-5}
A living POA&M tracks remediation progress. Structured prioritization reduces overlooked deficiencies. Documentation ensures accountability. Transparent tracking strengthens governance.
SPR-381
The [organization] shall designate an authorizing official for the system.{SV-MA-6}{CA-6}
These officials must be federal employees, and are responsible for reviewing the security authorization package, assessing the risks, and making the decision to authorize system operation. They shall ensure compliance with relevant organizational policies and standards and are accountable for the decision to accept the risks associated with operating the system. The authorizing officials must be empowered with the authority to oversee and enforce the implementation and maintenance of security controls in accordance with organizational requirements and applicable regulations.
SPR-382
The [organization] shall categorize the system and information it processes in accordance with FIPS 199.{SV-MA-6}{RA-2}
Impact categorization guides control selection. Formal classification ensures proportional protection. Defined impact levels strengthen risk alignment. Compliance supports federal mandate adherence.