CM-5(1) - Access Restrictions for Change | Automated Access Enforcement and Audit Records
(a) Enforce access restrictions using [Assignment: organization-defined automated mechanisms]; and
(b) Automatically generate audit records of the enforcement actions.
Restricting modifications to only authorized software and firmware is pivotal to mission integrity for space missions. If an unapproved binary were uploaded, it could inadvertently contain logic that disrupts attitude control or corrupts cryptographic keys. Thus, operators enforce strict whitelists identifying which code modules and versions are permitted. Ground stations perform cryptographic checks, verifying code signatures align with the official release. Such measures deter unauthorized or tampered files from being installed, effectively blocking potential insider threats or supply-chain exploits that could sabotage expensive, irreplaceable space assets.
Exploit ground system and use to maliciously to interact with the spacecraft
Sample Requirements
SPARTA ID
Requirement
Rationale/Additional Guidance/Notes
SPR-177
The [spacecraft] shall automatically generate audit records of the configuration management access enforcement actions.{SV-AC-4,SV-DCO-1}{CM-5(1)}
Recording enforcement actions provides accountability for access control decisions. This enables detection of policy violations or privilege misuse. Audit visibility strengthens governance. Security controls must themselves be auditable.