AU-12(3) - Audit Record Generation | Changes by Authorized Individuals
Provide and implement the capability for [Assignment: organization-defined individuals or roles] to change the logging to be performed on [Assignment: organization-defined system components] based on [Assignment: organization-defined selectable event criteria] within [Assignment: organization-defined time thresholds].
Adjusting what gets audited can be a high risk in a space platform since toggling audit parameters might mask unauthorized or anomalous activity. To mitigate that, only authorized personnel, identified via strong credentials or digital signatures, should be able to modify audit selections and thresholds. In effect, the spacecraft or its ground segment logs any changes to these settings and then transmits a notification to mission control. This ensures that the chain of custody for security-relevant logs remains intact, even if an adversary attempts to suppress or dilute critical evidence of tampering.
Exploit ground system and use to maliciously to interact with the spacecraft
Sample Requirements
SPARTA ID
Requirement
Rationale/Additional Guidance/Notes
SPR-165
The [spacecraft] shall generate audit records to capture changes made to audit record generation configurations by authorized users.{SV-DCO-1}{AU-12(3)}
Authorized users, including administrators, shall be identified, and the system shall record relevant information such as the user identity, date, time, and nature of changes made to the audit record generation settings.
SPR-166
The [spacecraft] shall provide the capability to modify the set of audited events (e.g., cyber-relevant data).{SV-DCO-1}{AU-12(3),AU-14}
Flexibility allows adaptation to evolving threats. Adjustable audit scope ensures relevant telemetry is captured. This supports threat-driven monitoring strategies. Controlled modification preserves operational balance.