CCSDS 350.0-G-3 - Space Communications Security (Consultative Committee for Space Data Systems)
Evidence request list. 17 controls, 17 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
CCSDS 350.0-G-3: Protocol Layer Security Requirements
350.0-G-3 sec.3.1: derivation of security requirements at each CCSDS protocol layer (data link, network, transport, application).
- mapping of security requirements to each CCSDS protocol layer
- rationale for where each security service is applied
- security requirements not allocated to protocol layers
350.0-G-3 sec.3.2: definition of mission-specific security requirements based on the threat assessment and mission sensitivity/classification.
- documented mission security requirements traceable to threats and mission classification
- mission security requirements undocumented or not threat-driven
CCSDS 350.0-G-3: Security Implementation Options
350.0-G-3 sec.5.3: applying security at the data link layer using the CCSDS Space Data Link Security (SDLS) protocol.
- use of the Space Data Link Security (SDLS) protocol where appropriate
- configuration of link-layer security services
- link-layer security available but not used for sensitive missions
350.0-G-3 sec.5.4: applying security at the network layer (e.g. IPSec) for IP-based space and ground communications.
- IPSec or equivalent for IP-based mission communications
- IP-based mission traffic unprotected at the network layer
350.0-G-3 sec.5.5: applying security at the transport layer (e.g. for the Space Packet Protocol) where appropriate.
- transport-layer security configuration for applicable protocols
- transport-layer security not considered
350.0-G-3 sec.5.6: applying security at the application layer (monitor and control, file transfer, hosted payloads, imagery, etc.).
- application-layer security for mission applications and hosted payloads
- application-layer data unprotected end to end
350.0-G-3 sec.5.7: combining security options across layers to achieve defence in depth without unnecessary duplication.
- rationale for the chosen combination of layer security options (defence in depth, avoiding redundant overhead)
- security applied redundantly or with gaps across layers
CCSDS 350.0-G-3: Security Implications and Selection
350.0-G-3 sec.6.4: comparison of the security implementation options against mission constraints (performance, key management, interoperability, cost).
- trade study comparing security options against mission constraints
- security options not compared against mission constraints
350.0-G-3 sec.6.5: selecting the appropriate security options for the mission and documenting the decision and residual risk.
- documented selection of security options with residual-risk acceptance
- traceability from threats/requirements to the selected options
- security option selection undocumented
- residual risk not accepted by an owner
CCSDS 350.0-G-3: Security Mechanisms
350.0-G-3 sec.4.1: confidentiality mechanisms (encryption) to protect telecommand, telemetry and payload data against disclosure.
- encryption applied to sensitive telecommand/telemetry/payload data
- approved cryptographic algorithms
- sensitive link or payload data unencrypted
- weak/non-approved algorithms
350.0-G-3 sec.4.2: authentication mechanisms (data origin and entity authentication) - notably authentication of telecommands to prevent unauthorised commanding.
- telecommand authentication (data origin authentication)
- entity authentication for ground-station/operator access
- telecommands not authenticated (spoofing/replay risk)
350.0-G-3 sec.4.3: integrity mechanisms to detect unauthorised or accidental modification of data in transit.
- integrity protection (MAC/authenticated encryption) on links
- detection of modification of commands/telemetry
- no integrity protection on critical links
350.0-G-3 sec.4.4: access control mechanisms restricting access to spacecraft, ground systems and data to authorised entities.
- access control to mission operations centre and ground systems
- authorisation rules for commanding and data access
- unrestricted access to ground/commanding systems
350.0-G-3 sec.4.5: availability mechanisms protecting against denial-of-service / jamming and ensuring continuity of mission communications.
- anti-jamming / anti-interference measures on the RF link
- redundancy and continuity of the ground segment
- no protection against link jamming/DoS
CCSDS 350.0-G-3: Space Security Concepts
350.0-G-3 sec.2.1: the fundamental information security services for space systems - confidentiality, integrity, availability, authentication and access control - and how they apply to space missions.
- mission security concept identifying which security services (CIA, authentication, access control) apply
- documentation of security objectives for the mission
- security services not identified for the mission
350.0-G-3 sec.2.2: a system security policy establishing the security objectives, rules and responsibilities for the space system.
- documented system security policy for the mission/ground/space segments
- no system security policy
350.0-G-3 sec.2.3: characterisation of threats against space missions (e.g. eavesdropping, jamming, spoofing, replay, denial of service, unauthorised access, software threats).
- threat analysis covering the space and ground segments and the communications links
- threat model feeding the risk assessment
- threats to the RF link / ground segment not analysed
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.