Skip to content

Evidence request lists

Space ISAC (Information Sharing and Analysis Center) - Threat Framework

Evidence request list. 40 controls, 40 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Asset Management

SISAC-02
Space Asset Inventory and Classification

Maintain an inventory of space and ground assets (satellites, ground stations, user terminals, links) classified by criticality and mission impact.

Artefacts an auditor will ask for
  • Space and ground segment asset register
  • Criticality and mission impact ratings
  • Asset owner mapping
  • Inventory update logs
Where this commonly fails
  • User terminals omitted from inventory
  • Mission impact ratings not refreshed
  • Ground station dependencies not mapped

Communications Link Threats

CT-1
RF Interference and Jamming

Radio frequency interference and intentional jamming of satellite communications must be detected and reported.

Artefacts an auditor will ask for
  • Threat intelligence sharing platform configuration
  • STIX/TAXII feed subscription and processing evidence
  • Threat actor profile and indicator-of-compromise repository
  • Space asset risk register with mission impact assessments
  • Ground segment security architecture documentation
  • RF link protection and anti-jamming control evidence
Where this commonly fails
  • Threat feeds ingested but not actioned in monitoring use cases
  • Indicators of compromise not correlated with internal telemetry
  • Ground segment cyber controls trail enterprise IT maturity
  • Supply chain assurance lacks tier-2 visibility
CT-2
GNSS Spoofing

Global Navigation Satellite System spoofing threats affecting positioning and timing must be shared.

Artefacts an auditor will ask for
  • Threat intelligence sharing platform configuration
  • STIX/TAXII feed subscription and processing evidence
  • Threat actor profile and indicator-of-compromise repository
  • Space asset risk register with mission impact assessments
  • Ground segment security architecture documentation
  • RF link protection and anti-jamming control evidence
Where this commonly fails
  • Threat feeds ingested but not actioned in monitoring use cases
  • Indicators of compromise not correlated with internal telemetry
  • Ground segment cyber controls trail enterprise IT maturity
  • Supply chain assurance lacks tier-2 visibility
CT-3
Signal Interception

Threats of unauthorized interception and exploitation of satellite communication signals must be monitored.

Artefacts an auditor will ask for
  • Threat intelligence sharing platform configuration
  • STIX/TAXII feed subscription and processing evidence
  • Threat actor profile and indicator-of-compromise repository
  • Space asset risk register with mission impact assessments
  • Ground segment security architecture documentation
  • RF link protection and anti-jamming control evidence
Where this commonly fails
  • Threat feeds ingested but not actioned in monitoring use cases
  • Indicators of compromise not correlated with internal telemetry
  • Ground segment cyber controls trail enterprise IT maturity
  • Supply chain assurance lacks tier-2 visibility
CT-4
Uplink and Downlink Manipulation

Threats of unauthorized manipulation of uplink commands or downlink telemetry must be identified.

Artefacts an auditor will ask for
  • Threat intelligence sharing platform configuration
  • STIX/TAXII feed subscription and processing evidence
  • Threat actor profile and indicator-of-compromise repository
  • Space asset risk register with mission impact assessments
  • Ground segment security architecture documentation
  • RF link protection and anti-jamming control evidence
Where this commonly fails
  • Threat feeds ingested but not actioned in monitoring use cases
  • Indicators of compromise not correlated with internal telemetry
  • Ground segment cyber controls trail enterprise IT maturity
  • Supply chain assurance lacks tier-2 visibility

Communications Security

SISAC-05
Command and Telemetry Link Protection

Protect telemetry, tracking and command (TT&C) links against jamming, spoofing and unauthorised command injection.

Artefacts an auditor will ask for
  • TT&C encryption and authentication design
  • Key management procedures for uplinks
  • Anti-spoof and anti-jam test results
  • Command authorisation matrix
Where this commonly fails
  • Legacy unencrypted uplinks in service
  • No replay protection on commands
  • Key rotation overdue

Coordination

SISAC-16
Cross Sector and Critical Infrastructure Coordination

Coordinate with sector ISACs, government CERTs and critical infrastructure partners that depend on space services for PNT and communications.

Artefacts an auditor will ask for
  • Cross sector contact directory
  • Joint exercise records
  • Dependency maps for downstream sectors
  • Coordination meeting minutes
Where this commonly fails
  • No contacts for downstream sectors
  • Dependencies not documented
  • Coordination only after incidents

Cryptography

SISAC-17
Encryption Key Lifecycle for Space Systems

Manage cryptographic keys used for TT&C, payload data and ground links across generation, distribution, rotation and revocation.

Artefacts an auditor will ask for
  • Key management plan
  • HSM inventory and audit logs
  • Key rotation schedule and evidence
  • Revocation and zeroisation procedures
Where this commonly fails
  • Keys never rotated post launch
  • No HSM, keys stored in software
  • Revocation untested

Detection

SISAC-09
On-Orbit Anomaly Detection

Detect anomalous telemetry, attitude changes and command sequences that could indicate cyber compromise of a spacecraft.

Artefacts an auditor will ask for
  • Telemetry baseline and anomaly rules
  • Alerting thresholds and runbooks
  • Operator console anomaly logs
  • Post anomaly investigation reports
Where this commonly fails
  • Anomaly rules only cover thermal and power
  • No cross correlation between command and telemetry
  • Alerts not routed to security operations

Endpoint Security

SISAC-18
User Terminal and Edge Device Security

Secure satellite user terminals, modems and edge devices against firmware tampering, hijack and unauthorised reconfiguration.

Artefacts an auditor will ask for
  • Terminal hardening guide
  • Firmware signing and verification records
  • Remote management access controls
  • Field tamper inspection reports
Where this commonly fails
  • Unsigned firmware accepted
  • Default management passwords
  • No tamper inspections in field

Exercises

SISAC-15
Tabletop and Red Team Exercises

Conduct regular tabletop and adversary emulation exercises focused on space specific TTPs and cross sector dependencies.

Artefacts an auditor will ask for
  • Exercise scenarios mapped to SPARTA
  • Participant lists and roles
  • After action reports
  • Tracked corrective actions
Where this commonly fails
  • Same scenario reused every year
  • Red team excluded from flight systems
  • Corrective actions not closed

Governance

SISAC-01
Membership and Trusted Community Onboarding

Establish formal membership with Space ISAC, complete vetting, and onboard authorised personnel to the trusted information sharing community.

Artefacts an auditor will ask for
  • Signed Space ISAC membership agreement
  • List of authorised personnel and roles
  • NDA and traffic light protocol (TLP) acknowledgements
  • Annual membership renewal records
Where this commonly fails
  • Stale authorised user list after staff turnover
  • Missing TLP handling acknowledgements
  • No documented vetting workflow

Governance and Collective Security

GC-1
Norms of Responsible Behavior

Space ISAC develops norms and guidelines for responsible behavior in space for collective security.

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Threat intelligence sharing platform configuration
  • STIX/TAXII feed subscription and processing evidence
  • Threat actor profile and indicator-of-compromise repository
Where this commonly fails
  • Policy document exists but lacks evidence of board approval or refresh cycle
  • Accountabilities defined on paper but not reflected in performance objectives
  • Threat feeds ingested but not actioned in monitoring use cases
  • Indicators of compromise not correlated with internal telemetry
  • Ground segment cyber controls trail enterprise IT maturity
GC-2
Public-Private Information Sharing

Universal public-private sharing mechanisms for threats must be maintained and accessible.

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Threat intelligence sharing platform configuration
  • STIX/TAXII feed subscription and processing evidence
  • Threat actor profile and indicator-of-compromise repository
Where this commonly fails
  • Policy document exists but lacks evidence of board approval or refresh cycle
  • Accountabilities defined on paper but not reflected in performance objectives
  • Threat feeds ingested but not actioned in monitoring use cases
  • Indicators of compromise not correlated with internal telemetry
  • Ground segment cyber controls trail enterprise IT maturity
GC-3
Cross-Sector Coordination

Coordination with other critical infrastructure ISACs ensures comprehensive threat awareness.

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Threat intelligence sharing platform configuration
  • STIX/TAXII feed subscription and processing evidence
  • Threat actor profile and indicator-of-compromise repository
Where this commonly fails
  • Policy document exists but lacks evidence of board approval or refresh cycle
  • Accountabilities defined on paper but not reflected in performance objectives
  • Threat feeds ingested but not actioned in monitoring use cases
  • Indicators of compromise not correlated with internal telemetry
  • Ground segment cyber controls trail enterprise IT maturity
GC-4
Technology-Agnostic Threat Formats

Standardized technology-agnostic formats must be used to encapsulate threats across different vendors.

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Threat intelligence sharing platform configuration
  • STIX/TAXII feed subscription and processing evidence
  • Threat actor profile and indicator-of-compromise repository
Where this commonly fails
  • Policy document exists but lacks evidence of board approval or refresh cycle
  • Accountabilities defined on paper but not reflected in performance objectives
  • Threat feeds ingested but not actioned in monitoring use cases
  • Indicators of compromise not correlated with internal telemetry
  • Ground segment cyber controls trail enterprise IT maturity

Ground Segment Threats

GT-1
Ground Station Cyber Attacks

Cyber threats targeting ground station networks and mission control systems must be monitored and shared.

Artefacts an auditor will ask for
  • Threat intelligence sharing platform configuration
  • STIX/TAXII feed subscription and processing evidence
  • Threat actor profile and indicator-of-compromise repository
  • Space asset risk register with mission impact assessments
  • Ground segment security architecture documentation
  • RF link protection and anti-jamming control evidence
Where this commonly fails
  • Threat feeds ingested but not actioned in monitoring use cases
  • Indicators of compromise not correlated with internal telemetry
  • Ground segment cyber controls trail enterprise IT maturity
  • Supply chain assurance lacks tier-2 visibility
GT-2
Physical Security Threats

Physical threats to ground infrastructure including sabotage and unauthorized access must be assessed.

Artefacts an auditor will ask for
  • Threat intelligence sharing platform configuration
  • STIX/TAXII feed subscription and processing evidence
  • Threat actor profile and indicator-of-compromise repository
  • Space asset risk register with mission impact assessments
  • Ground segment security architecture documentation
  • RF link protection and anti-jamming control evidence
Where this commonly fails
  • Threat feeds ingested but not actioned in monitoring use cases
  • Indicators of compromise not correlated with internal telemetry
  • Ground segment cyber controls trail enterprise IT maturity
  • Supply chain assurance lacks tier-2 visibility
GT-3
Supply Chain Compromise

Threats from compromised hardware or software components in the space supply chain must be identified.

Artefacts an auditor will ask for
  • Third-party risk assessment dossier per vendor
  • Signed contracts with required protection clauses
  • Ongoing assurance reports (SOC 2, ISO, audit findings)
  • Threat intelligence sharing platform configuration
  • STIX/TAXII feed subscription and processing evidence
  • Threat actor profile and indicator-of-compromise repository
Where this commonly fails
  • Vendor risk assessments not refreshed at the required cadence
  • Subcontractor flow-down clauses absent or weak in contracts
  • Threat feeds ingested but not actioned in monitoring use cases
  • Indicators of compromise not correlated with internal telemetry
  • Ground segment cyber controls trail enterprise IT maturity
GT-4
Social Engineering Attacks

Social engineering and phishing attacks targeting space operations personnel must be monitored and reported.

Artefacts an auditor will ask for
  • Threat intelligence sharing platform configuration
  • STIX/TAXII feed subscription and processing evidence
  • Threat actor profile and indicator-of-compromise repository
  • Space asset risk register with mission impact assessments
  • Ground segment security architecture documentation
  • RF link protection and anti-jamming control evidence
Where this commonly fails
  • Threat feeds ingested but not actioned in monitoring use cases
  • Indicators of compromise not correlated with internal telemetry
  • Ground segment cyber controls trail enterprise IT maturity
  • Supply chain assurance lacks tier-2 visibility

Incident Response

SISAC-11
Space System Incident Response

Maintain an incident response capability that addresses cyber events affecting space, ground and user segments with safe spacecraft recovery procedures.

Artefacts an auditor will ask for
  • Space cyber incident response plan
  • Safe mode and recovery procedures
  • Tabletop and live exercise records
  • Coordination contacts with Space ISAC and CERTs
Where this commonly fails
  • Plan addresses IT but not spacecraft
  • No safe mode triggers documented
  • Exercises exclude payload operators

Information Sharing

SISAC-04
Indicator and Threat Intelligence Sharing

Share and consume cyber threat indicators and tradecraft observations through Space ISAC channels using STIX or sector formats while honouring TLP markings.

Artefacts an auditor will ask for
  • STIX or MISP feed configuration
  • Submitted indicator reports
  • TLP handling procedure
  • Sharing volume and quality metrics
Where this commonly fails
  • Consumption only, no contributions back
  • TLP marking errors on outbound reports
  • No deduplication of indicators
SISAC-12
Threat Information Production and Quality

Produce timely, accurate and actionable threat reports for the Space ISAC community with provenance and confidence indicators.

Artefacts an auditor will ask for
  • Report templates with TLP and confidence fields
  • Editorial and review workflow
  • Submission quality metrics
  • Feedback log from community
Where this commonly fails
  • Reports lack confidence ratings
  • Sources not attributed
  • No peer review before submission

Infrastructure Security

SISAC-06
Ground Segment Hardening

Harden mission operations centres, ground stations and antenna sites against intrusion, lateral movement and insider misuse.

Artefacts an auditor will ask for
  • Ground segment network diagram
  • Hardening baselines and benchmarks
  • Segmentation and firewall rule reviews
  • Privileged access reviews
Where this commonly fails
  • Flat ground station networks
  • Default credentials on antenna controllers
  • Remote vendor access unmonitored

Operations

SISAC-19
Launch Phase Cybersecurity

Apply cybersecurity controls across pre-launch processing, launch operations and early orbit phases including range and launch provider interfaces.

Artefacts an auditor will ask for
  • Launch cyber risk assessment
  • Range interface security requirements
  • Pre-launch security checklist
  • Post launch lessons learned
Where this commonly fails
  • No cyber checklist for launch readiness
  • Range interfaces unscoped
  • Lessons learned not captured

Personnel Security

SISAC-13
Insider Threat Programme

Detect and mitigate insider threats across mission operations, software engineering and ground station staff including contractor populations.

Artefacts an auditor will ask for
  • Insider threat programme charter
  • Vetting and re-vetting records
  • User behaviour analytics outputs
  • Investigation case files
Where this commonly fails
  • Contractors out of scope
  • No behaviour analytics on engineering systems
  • Programme owner not defined

Programme Management

SISAC-20
Metrics, Maturity and Continuous Improvement

Measure space cybersecurity programme maturity, track indicator quality and mission risk and drive continuous improvement.

Artefacts an auditor will ask for
  • Programme metrics dashboard
  • Maturity self assessments
  • Improvement backlog with owners
  • Annual board report on space cyber risk
Where this commonly fails
  • Metrics focus on volume not outcomes
  • No maturity baseline
  • Improvement actions unowned

Resilience

SISAC-10
GNSS and Position, Navigation and Timing Resilience

Protect GNSS dependent services and timing against jamming, spoofing and degraded conditions through diversification and monitoring.

Artefacts an auditor will ask for
  • PNT dependency mapping
  • GNSS spoof and jam detection logs
  • Alternative timing source configuration
  • Resilience test reports
Where this commonly fails
  • Single GNSS constellation dependency
  • No holdover oscillator strategy
  • Spoof detection limited to receiver alarms

Software Security

SISAC-08
Flight Software Assurance

Apply secure development, code review and verification to flight software, payload firmware and on-board autonomy components.

Artefacts an auditor will ask for
  • Flight software SDLC procedure
  • Static and dynamic analysis reports
  • Code review records for safety critical modules
  • Independent verification and validation reports
Where this commonly fails
  • Heritage code reused without re-analysis
  • No fuzzing of command parsers
  • IV&V scope limited to functional tests

Space Segment Threats

ST-1
Satellite Cyber Intrusion

Threats from unauthorized access to satellite command and control systems must be identified and monitored.

Artefacts an auditor will ask for
  • Threat intelligence sharing platform configuration
  • STIX/TAXII feed subscription and processing evidence
  • Threat actor profile and indicator-of-compromise repository
  • Space asset risk register with mission impact assessments
  • Ground segment security architecture documentation
  • RF link protection and anti-jamming control evidence
Where this commonly fails
  • Threat feeds ingested but not actioned in monitoring use cases
  • Indicators of compromise not correlated with internal telemetry
  • Ground segment cyber controls trail enterprise IT maturity
  • Supply chain assurance lacks tier-2 visibility
ST-2
On-Orbit Interference

Threats of physical or electronic interference with operational satellites must be assessed and shared.

Artefacts an auditor will ask for
  • Threat intelligence sharing platform configuration
  • STIX/TAXII feed subscription and processing evidence
  • Threat actor profile and indicator-of-compromise repository
  • Space asset risk register with mission impact assessments
  • Ground segment security architecture documentation
  • RF link protection and anti-jamming control evidence
Where this commonly fails
  • Threat feeds ingested but not actioned in monitoring use cases
  • Indicators of compromise not correlated with internal telemetry
  • Ground segment cyber controls trail enterprise IT maturity
  • Supply chain assurance lacks tier-2 visibility
ST-3
Anti-Satellite Weapons

Kinetic and non-kinetic anti-satellite weapon threats must be monitored and intelligence shared across members.

Artefacts an auditor will ask for
  • Threat intelligence sharing platform configuration
  • STIX/TAXII feed subscription and processing evidence
  • Threat actor profile and indicator-of-compromise repository
  • Space asset risk register with mission impact assessments
  • Ground segment security architecture documentation
  • RF link protection and anti-jamming control evidence
Where this commonly fails
  • Threat feeds ingested but not actioned in monitoring use cases
  • Indicators of compromise not correlated with internal telemetry
  • Ground segment cyber controls trail enterprise IT maturity
  • Supply chain assurance lacks tier-2 visibility
ST-4
Space Debris as Threat

Intentional or unintentional space debris creating collision risks must be tracked and reported.

Artefacts an auditor will ask for
  • Threat intelligence sharing platform configuration
  • STIX/TAXII feed subscription and processing evidence
  • Threat actor profile and indicator-of-compromise repository
  • Space asset risk register with mission impact assessments
  • Ground segment security architecture documentation
  • RF link protection and anti-jamming control evidence
Where this commonly fails
  • Threat feeds ingested but not actioned in monitoring use cases
  • Indicators of compromise not correlated with internal telemetry
  • Ground segment cyber controls trail enterprise IT maturity
  • Supply chain assurance lacks tier-2 visibility

Supply Chain

SISAC-07
Supply Chain Risk Management for Space Hardware

Assess and mitigate cyber and provenance risks across satellite components, COTS modules, firmware and launch services.

Artefacts an auditor will ask for
  • Critical supplier list with risk ratings
  • Component provenance and SBOM records
  • Counterfeit parts screening procedure
  • Tamper evidence inspection logs
Where this commonly fails
  • No SBOM for flight software
  • Sub-tier suppliers not assessed
  • Counterfeit screening manual and inconsistent

Threat Intelligence

SISAC-03
Adversary TTP Mapping for Space Systems

Map known adversary tactics, techniques and procedures (TTPs) targeting space systems to internal controls using SPARTA or equivalent matrices.

Artefacts an auditor will ask for
  • SPARTA TTP coverage matrix
  • Threat actor profiles relevant to mission
  • Control to TTP mapping spreadsheet
  • Review minutes from threat working group
Where this commonly fails
  • Mapping limited to ground segment
  • No coverage of supply chain TTPs
  • Stale threat actor profiles

Threat Intelligence Sharing

TI-1
STIX Framework for Space

Structured Threat Information Expression (STIX) extensions for space-specific threats must be adopted.

Artefacts an auditor will ask for
  • Threat intelligence sharing platform configuration
  • STIX/TAXII feed subscription and processing evidence
  • Threat actor profile and indicator-of-compromise repository
  • Space asset risk register with mission impact assessments
  • Ground segment security architecture documentation
  • RF link protection and anti-jamming control evidence
Where this commonly fails
  • Threat feeds ingested but not actioned in monitoring use cases
  • Indicators of compromise not correlated with internal telemetry
  • Ground segment cyber controls trail enterprise IT maturity
  • Supply chain assurance lacks tier-2 visibility
TI-2
TAXII Transport Protocol

Trusted Automated Exchange of Intelligence Information (TAXII) must be used for machine-to-machine sharing.

Artefacts an auditor will ask for
  • Threat intelligence sharing platform configuration
  • STIX/TAXII feed subscription and processing evidence
  • Threat actor profile and indicator-of-compromise repository
  • Space asset risk register with mission impact assessments
  • Ground segment security architecture documentation
  • RF link protection and anti-jamming control evidence
Where this commonly fails
  • Threat feeds ingested but not actioned in monitoring use cases
  • Indicators of compromise not correlated with internal telemetry
  • Ground segment cyber controls trail enterprise IT maturity
  • Supply chain assurance lacks tier-2 visibility
TI-3
Indicator of Compromise Sharing

Indicators of compromise must be shared across the space community to enable collective defense.

Artefacts an auditor will ask for
  • Threat intelligence sharing platform configuration
  • STIX/TAXII feed subscription and processing evidence
  • Threat actor profile and indicator-of-compromise repository
  • Space asset risk register with mission impact assessments
  • Ground segment security architecture documentation
  • RF link protection and anti-jamming control evidence
Where this commonly fails
  • Threat feeds ingested but not actioned in monitoring use cases
  • Indicators of compromise not correlated with internal telemetry
  • Ground segment cyber controls trail enterprise IT maturity
  • Supply chain assurance lacks tier-2 visibility
TI-4
Threat Correlation and Analysis

Threat indicators must be correlated across the space attack surface for comprehensive situational awareness.

Artefacts an auditor will ask for
  • Threat intelligence sharing platform configuration
  • STIX/TAXII feed subscription and processing evidence
  • Threat actor profile and indicator-of-compromise repository
  • Space asset risk register with mission impact assessments
  • Ground segment security architecture documentation
  • RF link protection and anti-jamming control evidence
Where this commonly fails
  • Threat feeds ingested but not actioned in monitoring use cases
  • Indicators of compromise not correlated with internal telemetry
  • Ground segment cyber controls trail enterprise IT maturity
  • Supply chain assurance lacks tier-2 visibility

Vulnerability Management

SISAC-14
Vulnerability Management for Space Systems

Track, prioritise and remediate vulnerabilities across flight software, ground systems and user terminals with risk based scheduling.

Artefacts an auditor will ask for
  • Vulnerability register with SLA tracking
  • Patch deployment evidence for ground systems
  • On-orbit software update plans
  • Risk acceptance records for deferred fixes
Where this commonly fails
  • Spacecraft vulnerabilities not tracked
  • User terminal patching ad hoc
  • Risk acceptances without expiry
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Space ISAC (Information Sharing and Analysis Center) - Threat Framework framework page.