Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following:
(a) Effectiveness monitoring;
(b) Compliance monitoring; and
(c) Change monitoring.
Near real-time monitoring is usually practical only during specific phases (e.g., LEOP) or with continuous coverage. Prioritize which events merit near-real-time attention, failed command auth, unexpected mode transitions, key changes, parser faults, and ensure tooling and staffing align with predicted contact windows. Define what degrades gracefully when coverage drops so essential signals still surface at reduced cadence.
Maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions.
Space Threats Tagged by Control
ID
Description
Sample Requirements
SPARTA ID
Requirement
Rationale/Additional Guidance/Notes
SPR-385
The [organization] shall monitor, as part of the continuous monitoring strategy, the following: implementation of risk response measures; effectiveness of the risk response implementation; configuration changes that may impact security{SV-DCO-1}{CA-7(4)}