a. Develop and disseminate an organization-wide information security program plan that: 1. Provides an overview of the requirements for the security program and a description of the security program management controls and common controls in place or planned for meeting those requirements; 2. Includes the identification and assignment of roles, responsibilities, management commitment, coordination among organizational entities, and compliance; 3. Reflects the coordination among organizational entities responsible for information security; and 4. Is approved by a senior official with responsibility and accountability for the risk being incurred to organizational operations (including mission, functions, image, and reputation), organizational assets, individuals, other organizations, and the Nation; b. Review and update the organization-wide information security program plan [Assignment: organization-defined frequency] and following [Assignment: organization-defined events]; and c. Protect the information security program plan from unauthorized disclosure and modification.
| ID | Name | Description | D3FEND | |
| CM0088 | Organizational Policy | Documented cybersecurity policies establish the foundational governance framework that defines how an organization protects its information assets, assigns security responsibilities, and ensures consistent security behavior across all personnel and organizational levels. For space mission organizations, these policies must address the unique threat environment, operational constraints, and asset types associated with spacecraft, ground systems, and mission data, providing a coherent governance layer that connects organizational security objectives to the technical controls and operational practices implemented throughout the mission lifecycle. Well-documented policies ensure that personnel at all levels, from executive leadership through program management to operations staff, understand their security roles and responsibilities, reducing the probability of security failures attributable to ambiguity, inconsistency, or lack of guidance. Policies establish organizational security objectives, authorities, responsibilities, and required outcomes. Risk assessments, system requirements, standards, plans, and procedures translate those policies into technical controls and operational practices. During a security incident, approved incident response plans and procedures provide the actionable guidance needed to implement organizational policy and support timely decision-making. Mission organizations must identify the legal, regulatory, contractual, policy, and licensing requirements applicable to their activities and ensure that their cybersecurity policies address those obligations. Documented policies may therefore serve both organizational governance and compliance purposes. | ||
| ID | Description | |
| SPARTA ID | Requirement | Rationale/Additional Guidance/Notes |
|---|---|---|
| SPR-301 | The [organization] shall develop a security plan for the spacecraft.{SV-MA-6}{PL-2,PL-7,PM-1,SA-8(29),SA-8(30)} | A comprehensive security plan aligns controls with mission objectives. Clear articulation ensures consistent implementation. Planning integrates security into operations. Formal documentation strengthens accountability. |
| ID | Name | Description | |
|---|---|---|---|