SA-10(1) - Developer Configuration Management | Software and Firmware Integrity Verification

Require the developer of the system, system component, or system service to enable integrity verification of software and firmware components.


ID: SA-10(1)
Enhancement of : SA-10

Space Segment Guidance

The integrator must keep a master list of every software module, FPGA image, and board that composes the certified flight build because undocumented pieces invite hidden attack surfaces. Store the list in a configuration-management system with immutable audit logs, link each entry to its verification results and pedigree, and require change-control board approval before any new item receives a part number. During the launch countdown, the operations lead checks the on-orbit checksum report against this list, ensuring the vehicle carries only formally tested and approved artifacts.