IR-4(6) - Incident Handling | Insider Threats

Implement an incident handling capability for incidents involving insider threats.


ID: IR-4(6)
Enhancement of : IR-4

Space Segment Guidance

Insider threats to a spacecraft arise almost exclusively on the ground during design, manufacturing, key management, and flight-ops. The enhancement calls for tight coordination among cybersecurity responders, physical security, HR, and program protection so that anomalous behavior by cleared staff can be linked quickly to on-orbit effects. A practical implementation establishes an Insider Threat Working Group that meets after each contact window to review audit logs, build-server hashes, and access-badge data. When a workstation pushing a flight software patch shows odd badge activity, the group can immediately halt uplinks and task the flatsat for integrity checks. Procedures must extend across contractors and government nodes, using common event codes and secure channels so evidence remains admissible.