CM-5(5) - Access Restrictions for Change | Privilege Limitation for Production and Operation

(a) Limit privileges to change system components and system-related information within a production or operational environment; and (b) Review and reevaluate privileges [Assignment: organization-defined frequency].


ID: CM-5(5)
Enhancement of : CM-5

Space Segment Guidance

Automated remediation is challenging in the space domain due to limited on-orbit processing capability and the risk of false positives.  Nonetheless, having a partial automation pipeline can accelerate specific fixes, like rolling back to a trusted “golden” firmware image if a newly loaded module fails a built-in self-test.  The automation triggers only after thorough validation steps (e.g., verifying checksums or detecting repeated anomalies).  Although final decision authority often remains with the mission operations team, partial automation can buy time if an incident strikes during an off-hours communication gap, reducing damage until ground operators respond.