AC-17(4) - Remote Access | Privileged Commands and Access
(a) Authorize the execution of privileged commands and access to security-relevant information via remote access only in a format that provides assessable evidence and for the following needs: [Assignment: organization-defined needs]; and
(b) Document the rationale for remote access in the security plan for the system.
Privileged operations (e.g., crypto rekey, mode transitions, software loads) often warrant additional assurance. Consider independent checks or approvals, mode and precondition-aware gating, and enhanced logging that captures parameter values and verification steps. Holding points aligned to pass windows can help operators confirm effects before proceeding, while still allowing essential recovery actions when the vehicle is in a constrained state.
Precondition validation ensures hazardous commands are executed only under safe system states. This prevents execution under anomalous or compromised conditions. Independent verification reduces false activation risk. Safety and cyber controls must be integrated.
SPR-159
The [spacecraft] shall be capable of distinguishing critical versus non-critical commands.{SV-AC-8,SV-MA-3}{AC-17(4)}
Critical commands will vary across missions and systems but commonly include commands resulting in maneuvering of the spacecraft or modifying on-board configurations/software.
SPR-160
The [spacecraft] shall enforce access controls to restrict and monitor critical commands.{SV-AC-8,SV-AC-4}{AC-17(4)}
Critical commands will vary across missions and systems but commonly include commands resulting in maneuvering of the spacecraft or modifying on-board configurations/software.
SPR-161
The [spacecraft] shall log and monitor critical activities to detect and respond to unauthorized or malicious activities.{SV-DCO-1,SV-AC-4}{AC-6(9),AC-17(4)}
Critical commands will vary across missions and systems but commonly include commands resulting in maneuvering of the spacecraft or modifying on-board configurations/software.