Skip to content

Evidence request lists

CCSDS 350.0-G-3 - Space Communications Security (Consultative Committee for Space Data Systems)

Evidence request list. 17 controls, 17 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

CCSDS 350.0-G-3: Protocol Layer Security Requirements

CCSDS350-3.1
Protocol Layer Security Requirements

350.0-G-3 sec.3.1: derivation of security requirements at each CCSDS protocol layer (data link, network, transport, application).

Artefacts an auditor will ask for
  • mapping of security requirements to each CCSDS protocol layer
  • rationale for where each security service is applied
Where this commonly fails
  • security requirements not allocated to protocol layers
CCSDS350-3.2
Mission Security Requirements

350.0-G-3 sec.3.2: definition of mission-specific security requirements based on the threat assessment and mission sensitivity/classification.

Artefacts an auditor will ask for
  • documented mission security requirements traceable to threats and mission classification
Where this commonly fails
  • mission security requirements undocumented or not threat-driven

CCSDS 350.0-G-3: Security Implementation Options

CCSDS350-5.3
Data Link Layer Security

350.0-G-3 sec.5.3: applying security at the data link layer using the CCSDS Space Data Link Security (SDLS) protocol.

Artefacts an auditor will ask for
  • use of the Space Data Link Security (SDLS) protocol where appropriate
  • configuration of link-layer security services
Where this commonly fails
  • link-layer security available but not used for sensitive missions
CCSDS350-5.4
Network Layer Security (IPSec)

350.0-G-3 sec.5.4: applying security at the network layer (e.g. IPSec) for IP-based space and ground communications.

Artefacts an auditor will ask for
  • IPSec or equivalent for IP-based mission communications
Where this commonly fails
  • IP-based mission traffic unprotected at the network layer
CCSDS350-5.5
Transport Layer Security

350.0-G-3 sec.5.5: applying security at the transport layer (e.g. for the Space Packet Protocol) where appropriate.

Artefacts an auditor will ask for
  • transport-layer security configuration for applicable protocols
Where this commonly fails
  • transport-layer security not considered
CCSDS350-5.6
Application Layer Security

350.0-G-3 sec.5.6: applying security at the application layer (monitor and control, file transfer, hosted payloads, imagery, etc.).

Artefacts an auditor will ask for
  • application-layer security for mission applications and hosted payloads
Where this commonly fails
  • application-layer data unprotected end to end
CCSDS350-5.7
Security Option Combinations

350.0-G-3 sec.5.7: combining security options across layers to achieve defence in depth without unnecessary duplication.

Artefacts an auditor will ask for
  • rationale for the chosen combination of layer security options (defence in depth, avoiding redundant overhead)
Where this commonly fails
  • security applied redundantly or with gaps across layers

CCSDS 350.0-G-3: Security Implications and Selection

CCSDS350-6.4
Security Option Comparison

350.0-G-3 sec.6.4: comparison of the security implementation options against mission constraints (performance, key management, interoperability, cost).

Artefacts an auditor will ask for
  • trade study comparing security options against mission constraints
Where this commonly fails
  • security options not compared against mission constraints
CCSDS350-6.5
Security Option Selection

350.0-G-3 sec.6.5: selecting the appropriate security options for the mission and documenting the decision and residual risk.

Artefacts an auditor will ask for
  • documented selection of security options with residual-risk acceptance
  • traceability from threats/requirements to the selected options
Where this commonly fails
  • security option selection undocumented
  • residual risk not accepted by an owner

CCSDS 350.0-G-3: Security Mechanisms

CCSDS350-4.1
Confidentiality

350.0-G-3 sec.4.1: confidentiality mechanisms (encryption) to protect telecommand, telemetry and payload data against disclosure.

Artefacts an auditor will ask for
  • encryption applied to sensitive telecommand/telemetry/payload data
  • approved cryptographic algorithms
Where this commonly fails
  • sensitive link or payload data unencrypted
  • weak/non-approved algorithms
CCSDS350-4.2
Authentication

350.0-G-3 sec.4.2: authentication mechanisms (data origin and entity authentication) - notably authentication of telecommands to prevent unauthorised commanding.

Artefacts an auditor will ask for
  • telecommand authentication (data origin authentication)
  • entity authentication for ground-station/operator access
Where this commonly fails
  • telecommands not authenticated (spoofing/replay risk)
CCSDS350-4.3
Data Integrity

350.0-G-3 sec.4.3: integrity mechanisms to detect unauthorised or accidental modification of data in transit.

Artefacts an auditor will ask for
  • integrity protection (MAC/authenticated encryption) on links
  • detection of modification of commands/telemetry
Where this commonly fails
  • no integrity protection on critical links
CCSDS350-4.4
Access Control

350.0-G-3 sec.4.4: access control mechanisms restricting access to spacecraft, ground systems and data to authorised entities.

Artefacts an auditor will ask for
  • access control to mission operations centre and ground systems
  • authorisation rules for commanding and data access
Where this commonly fails
  • unrestricted access to ground/commanding systems
CCSDS350-4.5
Availability

350.0-G-3 sec.4.5: availability mechanisms protecting against denial-of-service / jamming and ensuring continuity of mission communications.

Artefacts an auditor will ask for
  • anti-jamming / anti-interference measures on the RF link
  • redundancy and continuity of the ground segment
Where this commonly fails
  • no protection against link jamming/DoS

CCSDS 350.0-G-3: Space Security Concepts

CCSDS350-2.1
Information Security Overview

350.0-G-3 sec.2.1: the fundamental information security services for space systems - confidentiality, integrity, availability, authentication and access control - and how they apply to space missions.

Artefacts an auditor will ask for
  • mission security concept identifying which security services (CIA, authentication, access control) apply
  • documentation of security objectives for the mission
Where this commonly fails
  • security services not identified for the mission
CCSDS350-2.2
System Security Policy

350.0-G-3 sec.2.2: a system security policy establishing the security objectives, rules and responsibilities for the space system.

Artefacts an auditor will ask for
  • documented system security policy for the mission/ground/space segments
Where this commonly fails
  • no system security policy
CCSDS350-2.3
Types of Threat

350.0-G-3 sec.2.3: characterisation of threats against space missions (e.g. eavesdropping, jamming, spoofing, replay, denial of service, unauthorised access, software threats).

Artefacts an auditor will ask for
  • threat analysis covering the space and ground segments and the communications links
  • threat model feeding the risk assessment
Where this commonly fails
  • threats to the RF link / ground segment not analysed
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.