a. Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]: 1. [Selection (one or more): organization-level; mission/business process-level; system-level] audit and accountability policy that: (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and 2. Procedures to facilitate the implementation of the audit and accountability policy and the associated audit and accountability controls; b. Designate an [Assignment: organization-defined official] to manage the development, documentation, and dissemination of the audit and accountability policy and procedures; and c. Review and update the current audit and accountability: 1. Policy [Assignment: organization-defined frequency] and following [Assignment: organization-defined events]; and 2. Procedures [Assignment: organization-defined frequency] and following [Assignment: organization-defined events].
| ID | Name | Description | D3FEND | |
| CM0088 | Organizational Policy | Documented cybersecurity policies establish the foundational governance framework that defines how an organization protects its information assets, assigns security responsibilities, and ensures consistent security behavior across all personnel and organizational levels. For space mission organizations, these policies must address the unique threat environment, operational constraints, and asset types associated with spacecraft, ground systems, and mission data, providing a coherent governance layer that connects organizational security objectives to the technical controls and operational practices implemented throughout the mission lifecycle. Well-documented policies ensure that personnel at all levels, from executive leadership through program management to operations staff, understand their security roles and responsibilities, reducing the probability of security failures attributable to ambiguity, inconsistency, or lack of guidance. Policies establish organizational security objectives, authorities, responsibilities, and required outcomes. Risk assessments, system requirements, standards, plans, and procedures translate those policies into technical controls and operational practices. During a security incident, approved incident response plans and procedures provide the actionable guidance needed to implement organizational policy and support timely decision-making. Mission organizations must identify the legal, regulatory, contractual, policy, and licensing requirements applicable to their activities and ensure that their cybersecurity policies address those obligations. Documented policies may therefore serve both organizational governance and compliance purposes. | ||
| ID | Description | |
| SPARTA ID | Requirement | Rationale/Additional Guidance/Notes |
|---|---|---|
| SPR-365 | The [organization] shall develop and maintain Audit and Accountability policy that specifies, at a minimum: the methods and procedures for auditing on-board events; the processes for capturing, recording, and reviewing audit logs; the criteria for audit event selection, frequency of audits, and data retention; the responsibilities for audit management and review.{SV-DCO-1}{AU-1} | Clear audit policy defines expectations for logging and review. Structured retention ensures forensic capability. Defined criteria strengthen monitoring consistency. Accountability deters misuse. |
| SPR-366 | The [organization] shall identify the applicable audit and accountability policies that cover the information on the spacecraft. {SV-DCO-1}{AU-1} | Ensuring policy applicability prevents coverage gaps. Alignment ensures consistent governance. Comprehensive audit scope strengthens detection capability. Policy clarity supports enforcement. |
| SPR-523 | The [organization] shall define and implement a common audit schema for flight and ground that supports event tiering, consistent identifiers/time bases, and dynamic elevation/suppression of categories by phase/mode; ground aggregators shall normalize and integrity‑check records.{SV-DCO-1}{AU-1,AU-6,AU-12} | Normalization supports cross-domain correlation. Tiered categories enable adaptive visibility. Integrity checks prevent log injection. Structured schema strengthens systemic monitoring. |
| ID | Name | Description | |
|---|---|---|---|