SC-1 - Policy and Procedures

a. Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]: 1. [Selection (one or more): organization-level; mission/business process-level; system-level] system and communications protection policy that: (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and 2. Procedures to facilitate the implementation of the system and communications protection policy and the associated system and communications protection controls; b. Designate an [Assignment: organization-defined official] to manage the development, documentation, and dissemination of the system and communications protection policy and procedures; and c. Review and update the current system and communications protection: 1. Policy [Assignment: organization-defined frequency] and following [Assignment: organization-defined events]; and 2. Procedures [Assignment: organization-defined frequency] and following [Assignment: organization-defined events].


ID: SC-1
Enhancements: 

Space Segment Guidance

System and communications protection policy for spacecraft should span RF links, TT&C networks, payload↔bus interfaces, and mission ground enclaves with lifecycle and mode awareness. Consider how protections behave under intermittent links, radiation upsets, and the high cost of on-orbit change; define how crypto, partitioning, boundary controls, and command/telemetry validation are specified, verified in twin/flatsat, activated, monitored, and maintained with partners. Policies that name trust boundaries, key custody/rotation, evidence required before enabling new paths, and fallback behavior in safe mode tend to hold up under real pass timelines.