AU-5(1) - Response to Audit Logging Process Failures | Storage Capacity Warning
Provide a warning to [Assignment: organization-defined personnel, roles, and/or locations] within [Assignment: organization-defined time period] when allocated audit log storage volume reaches [Assignment: organization-defined percentage] of repository maximum audit log storage capacity.
Automated responses may include switching to redundant stores, elevating downlink priority, throttling nonessential event categories, or snapshotting compact state summaries until capacity returns. It’s helpful to assess interactions with FDIR and power/thermal constraints so logging adaptations do not compete with safety-of-flight functions, and to surface any changes prominently in telemetry.
Failure of logging mechanisms may signal active tampering or resource exhaustion attacks. Immediate alerting ensures loss of visibility does not go unnoticed. Silent failure of audit systems creates blind spots exploitable by adversaries. Monitoring the monitors is critical to resilient detection.
SPR-70
The [spacecraft] shall provide an alert immediately to [at a minimum the mission director, administrators, and security officers] when the following failure events occur: [minimally but not limited to: auditing software/hardware errors; failures in the audit capturing mechanisms; and audit storage capacity reaching 95%, 99%, and 100%] of allocated capacity, including security component failover events; alerts shall include component identity, time, and fault reason.{SV-DCO-1}{AU-5,AU-5(1),AU-5(2),SI-4,SI-4(1),SI-4(7),SI-4(12),SI-4(24),SI-7(7)}
Intent is to have human on the ground be alerted to failures. This can be decomposed to SV to generate telemetry and to Ground to alert.
SPR-167
The [spacecraft] shall be configured to allocate audit record storage capacity in accordance with 1 week audit record storage requirements.{SV-DCO-1}{AU-4,AU-5,AU-5(1),AU-5(2)}
The [spacecraft] shall routinely report audit log storage utilization along with traditional health and status data during pre-determined passes.{SV-DCO-1}{AU-5(1)}
Monitoring storage usage prevents overflow conditions. Predictable reporting supports proactive resource management. Integration with health telemetry ensures visibility. Log retention reliability must be maintained.