SA-3 - System Development Life Cycle

a. Acquire, develop, and manage the system using [Assignment: organization-defined system development life cycle] that incorporates information security and privacy considerations; b. Define and document information security and privacy roles and responsibilities throughout the system development life cycle; c. Identify individuals having information security and privacy roles and responsibilities; and d. Integrate the organizational information security and privacy risk management process into system development life cycle activities.


ID: SA-3
Enhancements:  1 | 2 | 3

Space Segment Guidance

In the spacecraft SDLC, trace security requirements from mission hazards and flight rules into design, implementation, verification, and operations. Space constraints, radiation, power/thermal budgets, intermittent links, shape threat models, command acceptance checks, and update strategies. Plan early for digital-twin/HIL validation under realistic BER and timing, targeted fault-injection, and rehearsal of contingency procedures so security behaviors are demonstrated at pass cadence before flight, with clear acceptance criteria and rollback paths.