RA-5(5) - Vulnerability Monitoring and Scanning | Privileged Access
Implement privileged access authorization to [Assignment: organization-defined system components] for [Assignment: organization-defined vulnerability scanning activities].
Some assessments require elevated or authenticated access to achieve meaningful coverage (e.g., configuration audits of mission servers or consoles). Consider scheduling to avoid pass conflicts, scoping credentials to least privilege/read-only where possible, and segregating test traffic from TT&C paths. For flight software, pursue equivalent depth pre-flight in integration or flatsat environments, with on-orbit confirmation via image IDs, checksums, and configuration telemetry rather than intrusive scans.
Exploit ground system and use to maliciously to interact with the spacecraft
Sample Requirements
SPARTA ID
Requirement
Rationale/Additional Guidance/Notes
SPR-430
The [organization] shall employ privileged access authorization to applications and components for vulnerability scanning activities.{SV-AC-4}{RA-5(5)}