IR-1 - Policy and Procedures

a. Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]: 1. [Selection (one or more): organization-level; mission/business process-level; system-level] incident response policy that: (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and 2. Procedures to facilitate the implementation of the incident response policy and the associated incident response controls; b. Designate an [Assignment: organization-defined official] to manage the development, documentation, and dissemination of the incident response policy and procedures; and c. Review and update the current incident response: 1. Policy [Assignment: organization-defined frequency] and following [Assignment: organization-defined events]; and 2. Procedures [Assignment: organization-defined frequency] and following [Assignment: organization-defined events].


ID: IR-1
Enhancements: 

Space Segment Guidance

Incident response for spacecraft should reflect roles and authority across manufacturers, ground operators, partner stations, and external agencies, with phase/mode awareness and AOS/LOS constraints. Consider how detection, triage, and decision rights shift during LEOP or contingencies; what minimal evidence must be captured on-board when power is scarce; and how command release, FDIR actions, and revocation of stations/operators interact under time pressure. Playbooks that name decision owners, pre-authorize recovery steps, and specify cross-organization communications and evidence handling tend to hold up when timelines are measured in passes.