SA-1 - Policy and Procedures

a. Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]: 1. [Selection (one or more): organization-level; mission/business process-level; system-level] system and services acquisition policy that: (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and 2. Procedures to facilitate the implementation of the system and services acquisition policy and the associated system and services acquisition controls; b. Designate an [Assignment: organization-defined official] to manage the development, documentation, and dissemination of the system and services acquisition policy and procedures; and c. Review and update the current system and services acquisition: 1. Policy [Assignment: organization-defined frequency] and following [Assignment: organization-defined events]; and 2. Procedures [Assignment: organization-defined frequency] and following [Assignment: organization-defined events].


ID: SA-1
Enhancements: 

Space Segment Guidance

Acquisition policy for spacecraft should carry cybersecurity requirements across the whole mission system, space vehicle, TT&C ground, planning, partner stations, and data distribution, with lifecycle and mode awareness. Align expectations to milestones (PDR/CDR, I&T, launch/LEOP, on-orbit updates, disposal) and specify how evidence will be planned, generated, and accepted (twin/flatsat results, SBOMs, signed build/manifests, key-management artifacts). Address export/handling for design data, roles for independent verification, and how the “as-flown” security baseline and provenance are maintained and proven after launch.