IA-1 - Policy and Procedures

a. Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]: 1. [Selection (one or more): organization-level; mission/business process-level; system-level] identification and authentication policy that: (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and 2. Procedures to facilitate the implementation of the identification and authentication policy and the associated identification and authentication controls; b. Designate an [Assignment: organization-defined official] to manage the development, documentation, and dissemination of the identification and authentication policy and procedures; and c. Review and update the current identification and authentication: 1. Policy [Assignment: organization-defined frequency] and following [Assignment: organization-defined events]; and 2. Procedures [Assignment: organization-defined frequency] and following [Assignment: organization-defined events].


ID: IA-1
Enhancements: 

Space Segment Guidance

Identification and authentication policy for spacecraft should span ground, space, and partner stations with lifecycle and mode awareness. Consider how identities and authenticators are provisioned, activated, rotated, and revoked across phases; how AOS/LOS boundaries define session start/stop; what continues to authenticate in safe/low-power states; and how resets or clock drift affect caches and trust decisions. Policies can tie pre-launch key ceremonies and on-orbit rekey to command release workflows and audit, define revocation paths for stations/operators, and specify what narrows (e.g., command sets, session lifetimes) during contingencies while preserving essential recovery actions.