RA-5(2) - Vulnerability Monitoring and Scanning | Update Vulnerabilities to Be Scanned

Update the system vulnerabilities to be scanned [Selection (one or more): [Assignment: organization-defined frequency] ; prior to a new scan; when new vulnerabilities are identified and reported].


ID: RA-5(2)
Enhancement of : RA-5

Space Segment Guidance

Baseline vulnerability scanning of flight binaries occurs on the flatsat before each quarterly build release, but new findings emerge between cycles. This enhancement requires continuous monitoring of relevant CVE feeds, including real-time OS kernels and crypto libraries, and running delta scans within seven days of any critical disclosure. Results are compared against the frozen on-board image. If a high-severity flaw matches, the program schedules an out-of-cycle patch, validates it under radiation test, and uplinks the full image at the next safe window.