IR-4(1) - Incident Handling | Automated Incident Handling Processes

Support the incident handling process using [Assignment: organization-defined automated mechanisms].


ID: IR-4(1)
Enhancement of : IR-4

Space Segment Guidance

Automated incident handling capability on an orbiter centers on autonomous containment because contact windows gate real-time human response. The flight software should watch for events like repeated command authentication failures, unexpected privilege elevation, or sudden surges in internal network traffic. When a rule triggers, the response sequence logs the event to the protected audit buffer, forces the affected subsystem into a quiescent state, and queues a burst message on the following downlink. For example, detecting three bad decrypts in 30 seconds halts that receiver, rotates to a backup transponder, and flags the link as a suspect. Ground operators can then analyze without risking further compromise.