SA-4(2) - Acquisition Process | Design and Implementation Information for Controls
Require the developer of the system, system component, or system service to provide design and implementation information for the controls that includes: [Selection (one or more): security-relevant external system interfaces; high-level design; low-level design; source code or hardware schematics;
[Assignment: organization-defined design and implementation information]
] at [Assignment: organization-defined level of detail].
When deeper insight is needed, ask for design/implementation information sufficient to assess risk while protecting proprietary data. Examples include high-level architecture, ICDs, attack-surface summaries, fault-management interactions, and data-flow diagrams showing cryptographic boundaries and trust anchors. Define handling/marking requirements and redaction expectations so multinational teams can share what’s necessary without oversharing.
Exploit ground system and use to maliciously to interact with the spacecraft
Sample Requirements
SPARTA ID
Requirement
Rationale/Additional Guidance/Notes
SPR-433
The [organization] shall require the developer of the system, system component, or system services to provide design and implementation information for the controls that includes low-level security-relevant design information, source code, and hardware schematics.{SV-SP-4,SV-SP-5}{SA-4(2)}
Examples of good security practices would be using defense-in-depth tactics across the board, least-privilege being implemented, two factor authentication everywhere possible, using DevSecOps, implementing and validating adherence to secure coding standards, performing static code analysis, component/origin analysis for open source, fuzzing/dynamic analysis with abuse cases, etc.