CA-8(1) - Penetration Testing | Independent Penetration Testing Agent or Team

Employ an independent penetration testing agent or team to perform penetration testing on the system or system components.


ID: CA-8(1)
Enhancement of : CA-8

Space Segment Guidance

Penetration testing in the space segment often involves specialized “cyber range” environments or digital twins to avoid putting the actual spacecraft at risk.  This enhancement requires defining clear rules of engagement for these tests and ensuring that testers are appropriately trained to simulate real-world adversaries without triggering irreversible damage.  Because replacing an on-orbit asset is extremely expensive, developers typically replicate flight conditions, signal latency, radiation effects, and restricted power budgets in a lab environment.  Such “high-fidelity” testing ensures that discovered vulnerabilities accurately reflect how malicious actors might exploit fundamental components once in space, enabling more robust security fixes before launch or during scheduled update windows.