PL-8(2) - Security and Privacy Architectures | Supplier Diversity

Require that [Assignment: organization-defined controls] allocated to [Assignment: organization-defined locations and architectural layers] are obtained from different suppliers.


ID: PL-8(2)
Enhancement of : PL-8

Space Segment Guidance

Architecture documentation often spans models, interface definitions, and verification evidence. Keep these artifacts synchronized with the “as-built” and “as-flown” system, including identifiers (image IDs, APIDs, link configs) that show what is active on-orbit. Include rationale for key design choices (segmentation, crypto trust anchors, command pathways), anticipated operational limits, and the test/analysis basis (simulation, flatsat runs). Keeping this material current and accessible to operations staff accelerates troubleshooting under tight pass timelines.