AC-3 - Access Enforcement

Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.


ID: AC-3

Space Segment Guidance

For spacecraft, access enforcement typically means the flight system executes only those telecommands that are both authorized and context-appropriate. Consider layered checks that tie operator/station identity to allowed command families, verify spacecraft mode and preconditions (power/thermal margins, attitude), validate parameter ranges and sequencing, and apply rate/temporal limits to reduce operational risk. Enforcement mechanisms that survive resets, degraded links, and SEUs, and that clearly report accept/reject outcomes with reason codes, tend to simplify anomaly resolution. Ground implementations can align role profiles and consoles to the minimum needed for each phase, while on-board acceptance logic remains state-aware so the same command may be valid in one mode and rejected in another.