RA-1 - Policy and Procedures

a. Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]: 1. [Selection (one or more): organization-level; mission/business process-level; system-level] risk assessment policy that: (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and 2. Procedures to facilitate the implementation of the risk assessment policy and the associated risk assessment controls; b. Designate an [Assignment: organization-defined official] to manage the development, documentation, and dissemination of the risk assessment policy and procedures; and c. Review and update the current risk assessment: 1. Policy [Assignment: organization-defined frequency] and following [Assignment: organization-defined events]; and 2. Procedures [Assignment: organization-defined frequency] and following [Assignment: organization-defined events].


ID: RA-1
Enhancements: 

Space Segment Guidance

Risk assessment policy for spacecraft should reflect roles across manufacturers, integrators, launch services, mission ops, and partner stations, with lifecycle and mode awareness. Consider methods and reporting that align to phases (design/I&T, launch/LEOP, nominal, maintenance, disposal) and space-specific constraints, AOS/LOS, short pass windows, radiation effects, autonomy/FDIR, and limited on-orbit change authority. Define how inputs (threat intel, anomaly trends, vendor advisories) are validated, how likelihood/consequence are tailored to orbital hazards and operational timing, and how results drive engineering decisions, rehearsals, compensating controls, and contingency planning under time pressure.