Space ISAC (Information Sharing and Analysis Center) - Threat Framework
Evidence request list. 40 controls, 40 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Asset Management
Maintain an inventory of space and ground assets (satellites, ground stations, user terminals, links) classified by criticality and mission impact.
- Space and ground segment asset register
- Criticality and mission impact ratings
- Asset owner mapping
- Inventory update logs
- User terminals omitted from inventory
- Mission impact ratings not refreshed
- Ground station dependencies not mapped
Communications Link Threats
Radio frequency interference and intentional jamming of satellite communications must be detected and reported.
- Threat intelligence sharing platform configuration
- STIX/TAXII feed subscription and processing evidence
- Threat actor profile and indicator-of-compromise repository
- Space asset risk register with mission impact assessments
- Ground segment security architecture documentation
- RF link protection and anti-jamming control evidence
- Threat feeds ingested but not actioned in monitoring use cases
- Indicators of compromise not correlated with internal telemetry
- Ground segment cyber controls trail enterprise IT maturity
- Supply chain assurance lacks tier-2 visibility
Global Navigation Satellite System spoofing threats affecting positioning and timing must be shared.
- Threat intelligence sharing platform configuration
- STIX/TAXII feed subscription and processing evidence
- Threat actor profile and indicator-of-compromise repository
- Space asset risk register with mission impact assessments
- Ground segment security architecture documentation
- RF link protection and anti-jamming control evidence
- Threat feeds ingested but not actioned in monitoring use cases
- Indicators of compromise not correlated with internal telemetry
- Ground segment cyber controls trail enterprise IT maturity
- Supply chain assurance lacks tier-2 visibility
Threats of unauthorized interception and exploitation of satellite communication signals must be monitored.
- Threat intelligence sharing platform configuration
- STIX/TAXII feed subscription and processing evidence
- Threat actor profile and indicator-of-compromise repository
- Space asset risk register with mission impact assessments
- Ground segment security architecture documentation
- RF link protection and anti-jamming control evidence
- Threat feeds ingested but not actioned in monitoring use cases
- Indicators of compromise not correlated with internal telemetry
- Ground segment cyber controls trail enterprise IT maturity
- Supply chain assurance lacks tier-2 visibility
Threats of unauthorized manipulation of uplink commands or downlink telemetry must be identified.
- Threat intelligence sharing platform configuration
- STIX/TAXII feed subscription and processing evidence
- Threat actor profile and indicator-of-compromise repository
- Space asset risk register with mission impact assessments
- Ground segment security architecture documentation
- RF link protection and anti-jamming control evidence
- Threat feeds ingested but not actioned in monitoring use cases
- Indicators of compromise not correlated with internal telemetry
- Ground segment cyber controls trail enterprise IT maturity
- Supply chain assurance lacks tier-2 visibility
Communications Security
Protect telemetry, tracking and command (TT&C) links against jamming, spoofing and unauthorised command injection.
- TT&C encryption and authentication design
- Key management procedures for uplinks
- Anti-spoof and anti-jam test results
- Command authorisation matrix
- Legacy unencrypted uplinks in service
- No replay protection on commands
- Key rotation overdue
Coordination
Coordinate with sector ISACs, government CERTs and critical infrastructure partners that depend on space services for PNT and communications.
- Cross sector contact directory
- Joint exercise records
- Dependency maps for downstream sectors
- Coordination meeting minutes
- No contacts for downstream sectors
- Dependencies not documented
- Coordination only after incidents
Cryptography
Manage cryptographic keys used for TT&C, payload data and ground links across generation, distribution, rotation and revocation.
- Key management plan
- HSM inventory and audit logs
- Key rotation schedule and evidence
- Revocation and zeroisation procedures
- Keys never rotated post launch
- No HSM, keys stored in software
- Revocation untested
Detection
Detect anomalous telemetry, attitude changes and command sequences that could indicate cyber compromise of a spacecraft.
- Telemetry baseline and anomaly rules
- Alerting thresholds and runbooks
- Operator console anomaly logs
- Post anomaly investigation reports
- Anomaly rules only cover thermal and power
- No cross correlation between command and telemetry
- Alerts not routed to security operations
Endpoint Security
Secure satellite user terminals, modems and edge devices against firmware tampering, hijack and unauthorised reconfiguration.
- Terminal hardening guide
- Firmware signing and verification records
- Remote management access controls
- Field tamper inspection reports
- Unsigned firmware accepted
- Default management passwords
- No tamper inspections in field
Exercises
Conduct regular tabletop and adversary emulation exercises focused on space specific TTPs and cross sector dependencies.
- Exercise scenarios mapped to SPARTA
- Participant lists and roles
- After action reports
- Tracked corrective actions
- Same scenario reused every year
- Red team excluded from flight systems
- Corrective actions not closed
Governance
Establish formal membership with Space ISAC, complete vetting, and onboard authorised personnel to the trusted information sharing community.
- Signed Space ISAC membership agreement
- List of authorised personnel and roles
- NDA and traffic light protocol (TLP) acknowledgements
- Annual membership renewal records
- Stale authorised user list after staff turnover
- Missing TLP handling acknowledgements
- No documented vetting workflow
Governance and Collective Security
Space ISAC develops norms and guidelines for responsible behavior in space for collective security.
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Threat intelligence sharing platform configuration
- STIX/TAXII feed subscription and processing evidence
- Threat actor profile and indicator-of-compromise repository
- Policy document exists but lacks evidence of board approval or refresh cycle
- Accountabilities defined on paper but not reflected in performance objectives
- Threat feeds ingested but not actioned in monitoring use cases
- Indicators of compromise not correlated with internal telemetry
- Ground segment cyber controls trail enterprise IT maturity
Universal public-private sharing mechanisms for threats must be maintained and accessible.
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Threat intelligence sharing platform configuration
- STIX/TAXII feed subscription and processing evidence
- Threat actor profile and indicator-of-compromise repository
- Policy document exists but lacks evidence of board approval or refresh cycle
- Accountabilities defined on paper but not reflected in performance objectives
- Threat feeds ingested but not actioned in monitoring use cases
- Indicators of compromise not correlated with internal telemetry
- Ground segment cyber controls trail enterprise IT maturity
Coordination with other critical infrastructure ISACs ensures comprehensive threat awareness.
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Threat intelligence sharing platform configuration
- STIX/TAXII feed subscription and processing evidence
- Threat actor profile and indicator-of-compromise repository
- Policy document exists but lacks evidence of board approval or refresh cycle
- Accountabilities defined on paper but not reflected in performance objectives
- Threat feeds ingested but not actioned in monitoring use cases
- Indicators of compromise not correlated with internal telemetry
- Ground segment cyber controls trail enterprise IT maturity
Standardized technology-agnostic formats must be used to encapsulate threats across different vendors.
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Threat intelligence sharing platform configuration
- STIX/TAXII feed subscription and processing evidence
- Threat actor profile and indicator-of-compromise repository
- Policy document exists but lacks evidence of board approval or refresh cycle
- Accountabilities defined on paper but not reflected in performance objectives
- Threat feeds ingested but not actioned in monitoring use cases
- Indicators of compromise not correlated with internal telemetry
- Ground segment cyber controls trail enterprise IT maturity
Ground Segment Threats
Cyber threats targeting ground station networks and mission control systems must be monitored and shared.
- Threat intelligence sharing platform configuration
- STIX/TAXII feed subscription and processing evidence
- Threat actor profile and indicator-of-compromise repository
- Space asset risk register with mission impact assessments
- Ground segment security architecture documentation
- RF link protection and anti-jamming control evidence
- Threat feeds ingested but not actioned in monitoring use cases
- Indicators of compromise not correlated with internal telemetry
- Ground segment cyber controls trail enterprise IT maturity
- Supply chain assurance lacks tier-2 visibility
Physical threats to ground infrastructure including sabotage and unauthorized access must be assessed.
- Threat intelligence sharing platform configuration
- STIX/TAXII feed subscription and processing evidence
- Threat actor profile and indicator-of-compromise repository
- Space asset risk register with mission impact assessments
- Ground segment security architecture documentation
- RF link protection and anti-jamming control evidence
- Threat feeds ingested but not actioned in monitoring use cases
- Indicators of compromise not correlated with internal telemetry
- Ground segment cyber controls trail enterprise IT maturity
- Supply chain assurance lacks tier-2 visibility
Threats from compromised hardware or software components in the space supply chain must be identified.
- Third-party risk assessment dossier per vendor
- Signed contracts with required protection clauses
- Ongoing assurance reports (SOC 2, ISO, audit findings)
- Threat intelligence sharing platform configuration
- STIX/TAXII feed subscription and processing evidence
- Threat actor profile and indicator-of-compromise repository
- Vendor risk assessments not refreshed at the required cadence
- Subcontractor flow-down clauses absent or weak in contracts
- Threat feeds ingested but not actioned in monitoring use cases
- Indicators of compromise not correlated with internal telemetry
- Ground segment cyber controls trail enterprise IT maturity
Social engineering and phishing attacks targeting space operations personnel must be monitored and reported.
- Threat intelligence sharing platform configuration
- STIX/TAXII feed subscription and processing evidence
- Threat actor profile and indicator-of-compromise repository
- Space asset risk register with mission impact assessments
- Ground segment security architecture documentation
- RF link protection and anti-jamming control evidence
- Threat feeds ingested but not actioned in monitoring use cases
- Indicators of compromise not correlated with internal telemetry
- Ground segment cyber controls trail enterprise IT maturity
- Supply chain assurance lacks tier-2 visibility
Incident Response
Maintain an incident response capability that addresses cyber events affecting space, ground and user segments with safe spacecraft recovery procedures.
- Space cyber incident response plan
- Safe mode and recovery procedures
- Tabletop and live exercise records
- Coordination contacts with Space ISAC and CERTs
- Plan addresses IT but not spacecraft
- No safe mode triggers documented
- Exercises exclude payload operators
Information Sharing
Share and consume cyber threat indicators and tradecraft observations through Space ISAC channels using STIX or sector formats while honouring TLP markings.
- STIX or MISP feed configuration
- Submitted indicator reports
- TLP handling procedure
- Sharing volume and quality metrics
- Consumption only, no contributions back
- TLP marking errors on outbound reports
- No deduplication of indicators
Produce timely, accurate and actionable threat reports for the Space ISAC community with provenance and confidence indicators.
- Report templates with TLP and confidence fields
- Editorial and review workflow
- Submission quality metrics
- Feedback log from community
- Reports lack confidence ratings
- Sources not attributed
- No peer review before submission
Infrastructure Security
Harden mission operations centres, ground stations and antenna sites against intrusion, lateral movement and insider misuse.
- Ground segment network diagram
- Hardening baselines and benchmarks
- Segmentation and firewall rule reviews
- Privileged access reviews
- Flat ground station networks
- Default credentials on antenna controllers
- Remote vendor access unmonitored
Operations
Apply cybersecurity controls across pre-launch processing, launch operations and early orbit phases including range and launch provider interfaces.
- Launch cyber risk assessment
- Range interface security requirements
- Pre-launch security checklist
- Post launch lessons learned
- No cyber checklist for launch readiness
- Range interfaces unscoped
- Lessons learned not captured
Personnel Security
Detect and mitigate insider threats across mission operations, software engineering and ground station staff including contractor populations.
- Insider threat programme charter
- Vetting and re-vetting records
- User behaviour analytics outputs
- Investigation case files
- Contractors out of scope
- No behaviour analytics on engineering systems
- Programme owner not defined
Programme Management
Measure space cybersecurity programme maturity, track indicator quality and mission risk and drive continuous improvement.
- Programme metrics dashboard
- Maturity self assessments
- Improvement backlog with owners
- Annual board report on space cyber risk
- Metrics focus on volume not outcomes
- No maturity baseline
- Improvement actions unowned
Resilience
Protect GNSS dependent services and timing against jamming, spoofing and degraded conditions through diversification and monitoring.
- PNT dependency mapping
- GNSS spoof and jam detection logs
- Alternative timing source configuration
- Resilience test reports
- Single GNSS constellation dependency
- No holdover oscillator strategy
- Spoof detection limited to receiver alarms
Software Security
Apply secure development, code review and verification to flight software, payload firmware and on-board autonomy components.
- Flight software SDLC procedure
- Static and dynamic analysis reports
- Code review records for safety critical modules
- Independent verification and validation reports
- Heritage code reused without re-analysis
- No fuzzing of command parsers
- IV&V scope limited to functional tests
Space Segment Threats
Threats from unauthorized access to satellite command and control systems must be identified and monitored.
- Threat intelligence sharing platform configuration
- STIX/TAXII feed subscription and processing evidence
- Threat actor profile and indicator-of-compromise repository
- Space asset risk register with mission impact assessments
- Ground segment security architecture documentation
- RF link protection and anti-jamming control evidence
- Threat feeds ingested but not actioned in monitoring use cases
- Indicators of compromise not correlated with internal telemetry
- Ground segment cyber controls trail enterprise IT maturity
- Supply chain assurance lacks tier-2 visibility
Threats of physical or electronic interference with operational satellites must be assessed and shared.
- Threat intelligence sharing platform configuration
- STIX/TAXII feed subscription and processing evidence
- Threat actor profile and indicator-of-compromise repository
- Space asset risk register with mission impact assessments
- Ground segment security architecture documentation
- RF link protection and anti-jamming control evidence
- Threat feeds ingested but not actioned in monitoring use cases
- Indicators of compromise not correlated with internal telemetry
- Ground segment cyber controls trail enterprise IT maturity
- Supply chain assurance lacks tier-2 visibility
Kinetic and non-kinetic anti-satellite weapon threats must be monitored and intelligence shared across members.
- Threat intelligence sharing platform configuration
- STIX/TAXII feed subscription and processing evidence
- Threat actor profile and indicator-of-compromise repository
- Space asset risk register with mission impact assessments
- Ground segment security architecture documentation
- RF link protection and anti-jamming control evidence
- Threat feeds ingested but not actioned in monitoring use cases
- Indicators of compromise not correlated with internal telemetry
- Ground segment cyber controls trail enterprise IT maturity
- Supply chain assurance lacks tier-2 visibility
Intentional or unintentional space debris creating collision risks must be tracked and reported.
- Threat intelligence sharing platform configuration
- STIX/TAXII feed subscription and processing evidence
- Threat actor profile and indicator-of-compromise repository
- Space asset risk register with mission impact assessments
- Ground segment security architecture documentation
- RF link protection and anti-jamming control evidence
- Threat feeds ingested but not actioned in monitoring use cases
- Indicators of compromise not correlated with internal telemetry
- Ground segment cyber controls trail enterprise IT maturity
- Supply chain assurance lacks tier-2 visibility
Supply Chain
Assess and mitigate cyber and provenance risks across satellite components, COTS modules, firmware and launch services.
- Critical supplier list with risk ratings
- Component provenance and SBOM records
- Counterfeit parts screening procedure
- Tamper evidence inspection logs
- No SBOM for flight software
- Sub-tier suppliers not assessed
- Counterfeit screening manual and inconsistent
Threat Intelligence
Map known adversary tactics, techniques and procedures (TTPs) targeting space systems to internal controls using SPARTA or equivalent matrices.
- SPARTA TTP coverage matrix
- Threat actor profiles relevant to mission
- Control to TTP mapping spreadsheet
- Review minutes from threat working group
- Mapping limited to ground segment
- No coverage of supply chain TTPs
- Stale threat actor profiles
Threat Intelligence Sharing
Structured Threat Information Expression (STIX) extensions for space-specific threats must be adopted.
- Threat intelligence sharing platform configuration
- STIX/TAXII feed subscription and processing evidence
- Threat actor profile and indicator-of-compromise repository
- Space asset risk register with mission impact assessments
- Ground segment security architecture documentation
- RF link protection and anti-jamming control evidence
- Threat feeds ingested but not actioned in monitoring use cases
- Indicators of compromise not correlated with internal telemetry
- Ground segment cyber controls trail enterprise IT maturity
- Supply chain assurance lacks tier-2 visibility
Trusted Automated Exchange of Intelligence Information (TAXII) must be used for machine-to-machine sharing.
- Threat intelligence sharing platform configuration
- STIX/TAXII feed subscription and processing evidence
- Threat actor profile and indicator-of-compromise repository
- Space asset risk register with mission impact assessments
- Ground segment security architecture documentation
- RF link protection and anti-jamming control evidence
- Threat feeds ingested but not actioned in monitoring use cases
- Indicators of compromise not correlated with internal telemetry
- Ground segment cyber controls trail enterprise IT maturity
- Supply chain assurance lacks tier-2 visibility
Indicators of compromise must be shared across the space community to enable collective defense.
- Threat intelligence sharing platform configuration
- STIX/TAXII feed subscription and processing evidence
- Threat actor profile and indicator-of-compromise repository
- Space asset risk register with mission impact assessments
- Ground segment security architecture documentation
- RF link protection and anti-jamming control evidence
- Threat feeds ingested but not actioned in monitoring use cases
- Indicators of compromise not correlated with internal telemetry
- Ground segment cyber controls trail enterprise IT maturity
- Supply chain assurance lacks tier-2 visibility
Threat indicators must be correlated across the space attack surface for comprehensive situational awareness.
- Threat intelligence sharing platform configuration
- STIX/TAXII feed subscription and processing evidence
- Threat actor profile and indicator-of-compromise repository
- Space asset risk register with mission impact assessments
- Ground segment security architecture documentation
- RF link protection and anti-jamming control evidence
- Threat feeds ingested but not actioned in monitoring use cases
- Indicators of compromise not correlated with internal telemetry
- Ground segment cyber controls trail enterprise IT maturity
- Supply chain assurance lacks tier-2 visibility
Vulnerability Management
Track, prioritise and remediate vulnerabilities across flight software, ground systems and user terminals with risk based scheduling.
- Vulnerability register with SLA tracking
- Patch deployment evidence for ground systems
- On-orbit software update plans
- Risk acceptance records for deferred fixes
- Spacecraft vulnerabilities not tracked
- User terminal patching ad hoc
- Risk acceptances without expiry
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Space ISAC (Information Sharing and Analysis Center) - Threat Framework framework page.