CM-5(5) - Access Restrictions for Change | Privilege Limitation for Production and Operation
(a) Limit privileges to change system components and system-related information within a production or operational environment; and
(b) Review and reevaluate privileges [Assignment: organization-defined frequency].
Automated remediation is challenging in the space domain due to limited on-orbit processing capability and the risk of false positives. Nonetheless, having a partial automation pipeline can accelerate specific fixes, like rolling back to a trusted “golden” firmware image if a newly loaded module fails a built-in self-test. The automation triggers only after thorough validation steps (e.g., verifying checksums or detecting repeated anomalies). Although final decision authority often remains with the mission operations team, partial automation can buy time if an incident strikes during an off-hours communication gap, reducing damage until ground operators respond.
Least privilege limits damage from compromised processes or insider misuse. Processes receive only the minimum access necessary for assigned functions. This reduces lateral movement and privilege escalation pathways. In deterministic spacecraft systems, privilege boundaries must be tightly defined and enforced.
SPR-178
The [spacecraft] shall limit changes to system components and system-related information during operations.{SV-SP-9,SV-AC-4}{CM-5(5)}
Uncontrolled changes during operations introduce instability and increase exploitation risk. Restricting modifications reduces insider threat and unauthorized configuration drift. Operational stability is critical in space systems where rollback may be impossible. Controlled change windows preserve mission integrity.
SPR-418
The [organization] shall define a process to limit privileges to change system components and system-related information within a production or operational environment.{SV-AC-4,SV-AC-1}{CM-5(5)}