PM-14 - Testing, Training, and Monitoring

a. Implement a process for ensuring that organizational plans for conducting security and privacy testing, training, and monitoring activities associated with organizational systems: 1. Are developed and maintained; and 2. Continue to be executed; and b. Review testing, training, and monitoring plans for consistency with the organizational risk management strategy and organization-wide priorities for risk response actions.


ID: PM-14
Enhancements: 

Space Segment Guidance

A robust testing, training, and monitoring program is vital for maintaining continuous readiness across the entire space mission lifecycle. In practice, this includes establishing simulation-based rehearsals of anomaly response, especially for highly specialized operations like unexpected radiation surges or off-nominal orbital maneuvers. Training should be role-based, targeting key workforce categories—from spacecraft operators and ground-segment security teams to payload developers—so each group fully understands how cyber and kinetic threats can impact flight operations. Monitoring efforts extend beyond routine audits; they involve ongoing data collection and analysis of relevant telemetry, logs, and threat intelligence to validate system resilience. Together, these activities cultivate a feedback loop where lessons learned in tests and simulations continuously improve workforce preparedness, ultimately helping safeguard mission objectives despite potential adversities or evolving threat landscapes.