AC-17(6) - Remote Access | Protection of Mechanism Information

Protect information about remote access mechanisms from unauthorized use and disclosure.


ID: AC-17(6)
Enhancement of : AC-17

Space Segment Guidance

Privileged commands sent over remote connections pose a distinct risk for space systems, as an adversary that successfully impersonates a ground controller or intercepts a command uplink can cause catastrophic mission loss.  Under this enhancement, organizations enforce stringent safeguards for privileged actions executed via remote channels.  In a satellite context, that might include special cryptographic “dual keys” requiring two separate ground operators or operational centers to concur on a destructive or high-impact command, like deploying a critical payload or activating “safe mode.” Alternatively, the craft could enforce multi-factor authentication, where each privileged command must be countersigned by a second on-board security module that checks for timing anomalies, authorized identity, and command integrity.  Such measures may increase operational complexity but significantly mitigate the risk of single-actor compromise, especially relevant for long-duration missions where trust boundaries are blurred across different ground stations or international stakeholders.  This ensures that no single compromised login can reorder orbital elements or jeopardize the entire system.