SA-10(7) - Developer Configuration Management | Security and Privacy Representatives

Require [Assignment: organization-defined security and privacy representatives] to be included in the [Assignment: organization-defined configuration change management and control process].


ID: SA-10(7)
Enhancement of : SA-10

Space Segment Guidance

Automated integrity checks catch silent drifts between the authoritative repository and work copies used in late-night troubleshooting. A continuous integration pipeline pulls the trunk branch nightly, rebuilds every image, and compares the hash to the last approved release. Any mismatch raises a ticket that blocks the following code review until resolved. The same pipeline polls jump drives connected to the flatsat, rejecting files whose hashes are absent in the configuration database, protecting against sneaker-net introductions of rogue tools or unsigned patches.