IR-5 - Incident Monitoring

Track and document incidents.


ID: IR-5
Enhancements:  1

Space Segment Guidance

Continuous incident monitoring in orbit must blend on-board and ground capabilities. The flight computer logs authentication failures, unexpected resets, and sensor outliers to a protected ring buffer sized for the most prolonged expected blackout. At each pass, the ground station harvests the buffer, merges records with firewall alerts, and feeds a mission-tailored SIEM that flags patterns against a library of space-specific TTPs. Analysts review dashboards during real-time passes and complete a full correlation within two hours of data receipt, satisfying the timeliness required by the control.