a. Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]: 1. [Selection (one or more): organization-level; mission/business process-level; system-level] maintenance policy that: (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and 2. Procedures to facilitate the implementation of the maintenance policy and the associated maintenance controls; b. Designate an [Assignment: organization-defined official] to manage the development, documentation, and dissemination of the maintenance policy and procedures; and c. Review and update the current maintenance: 1. Policy [Assignment: organization-defined frequency] and following [Assignment: organization-defined events]; and 2. Procedures [Assignment: organization-defined frequency] and following [Assignment: organization-defined events].
| ID | Name | Description | D3FEND | |
| CM0088 | Organizational Policy | Documented cybersecurity policies establish the foundational governance framework that defines how an organization protects its information assets, assigns security responsibilities, and ensures consistent security behavior across all personnel and organizational levels. For space mission organizations, these policies must address the unique threat environment, operational constraints, and asset types associated with spacecraft, ground systems, and mission data, providing a coherent governance layer that connects organizational security objectives to the technical controls and operational practices implemented throughout the mission lifecycle. Well-documented policies ensure that personnel at all levels, from executive leadership through program management to operations staff, understand their security roles and responsibilities, reducing the probability of security failures attributable to ambiguity, inconsistency, or lack of guidance. Policies establish organizational security objectives, authorities, responsibilities, and required outcomes. Risk assessments, system requirements, standards, plans, and procedures translate those policies into technical controls and operational practices. During a security incident, approved incident response plans and procedures provide the actionable guidance needed to implement organizational policy and support timely decision-making. Mission organizations must identify the legal, regulatory, contractual, policy, and licensing requirements applicable to their activities and ensure that their cybersecurity policies address those obligations. Documented policies may therefore serve both organizational governance and compliance purposes. | ||
| ID | Description | |
| SPARTA ID | Requirement | Rationale/Additional Guidance/Notes |
|---|---|---|
| SPR-372 | The [organization] shall develop and document program-specific system maintenance policies for performing maintenance on the spacecraft hardware (pre-launch) and software (post-launch). {SV-SP-9,SV-SP-4}{MA-1} | Maintenance must preserve system integrity. Defined policies prevent unauthorized modification. Lifecycle control supports traceability. Maintenance governance strengthens resilience. |
| ID | Name | Description | |
|---|---|---|---|