IR-4(13) - Incident Handling | Behavior Analysis

Analyze anomalous or suspected adversarial behavior in or related to [Assignment: organization-defined environments or resources].


ID: IR-4(13)
Enhancement of : IR-4

Space Segment Guidance

Eradication and reconstitution may require reloading software, rotating cryptographic material, or reconfiguring ground/TT&C paths, often across multiple short contacts. Consider staged updates with chunking and commit markers, dual-bank/rollback activation, and tightly coordinated windows across partners to avoid conflicting actions. Verify outcomes via telemetry (active image, config hashes, key state) and reconcile command histories so a single “source of truth” documents what changed and why.