Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following:
(a) Effectiveness monitoring;
(b) Compliance monitoring; and
(c) Change monitoring.
Near real-time monitoring is usually practical only during specific phases (e.g., LEOP) or with continuous coverage. Prioritize which events merit near-real-time attention, failed command auth, unexpected mode transitions, key changes, parser faults, and ensure tooling and staffing align with predicted contact windows. Define what degrades gracefully when coverage drops so essential signals still surface at reduced cadence.
Continuous monitoring maintains persistent, real-time or near-real-time visibility into the security posture of spacecraft, ground systems, and mission networks, providing the ongoing situational awareness required to support informed risk management decisions throughout the mission lifecycle. Unlike point-in-time assessments that capture a snapshot of security posture at a specific moment, continuous monitoring detects changes in system configuration, software vulnerabilities, threat indicators, and control effectiveness as they occur, enabling faster detection of and response to security-relevant events before they escalate into mission-impacting incidents. For space missions, continuous monitoring spans both the cyber domain, including ground system network activity, software configuration compliance, vulnerability status, and access control events, and the physical and operational domains, including spacecraft telemetry indicators of anomalous behavior, link quality indicators of potential radio frequency (RF) interference, and space domain awareness data indicating proximity threats. The output of continuous monitoring feeds directly into risk management decision-making, providing mission owners and security teams with the current information needed to prioritize remediation actions, authorize changes, and adjust defensive posture in response to the evolving threat and vulnerability landscape.
Space Threats Tagged by Control
ID
Description
Sample Requirements
SPARTA ID
Requirement
Rationale/Additional Guidance/Notes
SPR-385
The [organization] shall monitor, as part of the continuous monitoring strategy, the following: implementation of risk response measures; effectiveness of the risk response implementation; configuration changes that may impact security{SV-DCO-1}{CA-7(4)}