Official record

Cybersecurity Principles for Space Systems

Record date: 2020-09-10

Space Policy Directive-5 of September 4, 2020 Cybersecurity Principles for Space Systems Memorandum for the Vice President[,] the Secretary of State[,] the Secretary of Defense[,] the Attorney General[,] the Secretary of Commerce[,] the Secretary of Transportation[,] the Secretary of Homeland Security[,] the Director of the Office of Management and Budget[,] the Assistant to the President for National Security Affairs[,] the Director of National Intelligence[,] the Director of the Central Intelligence Agency[,] the Director of the National Security Agency[,] the Director of the National Reconnaissance Office[,] the Administrator of the National

What this record contains

Federal Register document
2020-20150
Publication date
2020-09-10
Citation
85 FR 56155
Issuing office
Executive Office of the President

Official record excerpt

Space Policy Directive-5 of September 4, 2020 Cybersecurity Principles for Space Systems Memorandum for the Vice President[,] the Secretary of State[,] the Secretary of Defense[,] the Attorney General[,] the Secretary of Commerce[,] the Secretary of Transportation[,] the Secretary of Homeland Security[,] the Director of the Office of Management and Budget[,] the Assistant to the President for National Security Affairs[,] the Director of National Intelligence[,] the Director of the Central Intelligence Agency[,] the Director of the National Security Agency[,] the Director of the National Reconnaissance Office[,] the Administrator of the National Aeronautics and Space Administration[,] the Director of the Office of Science and Technology Policy[,] the Chairman of the Joint Chiefs of Staff[, and] the Chairman of the Federal Communications Commission Section 1 . Background. The United States considers unfettered freedom to operate in space vital to advancing the security, economic prosperity, and scientific knowledge of the Nation. Space systems enable key functions such as global communications; positioning, navigation, and timing; scientific observation; exploration; weather monitoring; and multiple vital national security applications. Therefore, it is essential to protect space systems from cyber incidents in order to prevent disruptions to their ability to provide reliable and efficient contributions to the operations of the Nation's critical infrastructure. Space systems are reliant on information systems and networks from design conceptualization through launch and flight operations. Further, the transmission of command and control and mission information between space vehicles and ground networks relies on the use of radio-frequency-dependent wireless communication channels. These systems, networks, and channels can be vulnerable to malicious activities that can deny, degrade, or disrupt space operations, or even destroy satellites. Examples of malicious cyber activities harmful to space operations include spoofing sensor data; corrupting sensor systems; jamming or sending unauthorized commands for guidance and control; injecting malicious code; and conducting denial-of-service attacks. Consequences of such activities could include loss of mission data; decreased lifespan or capability of space systems or constellations; or the loss of positive control of space vehicles, potentially resulting in collisions that can impair systems or generate harmful orbital debris. The National Security Strategy of December 2017 states that “[t]he United States must maintain our leadership and freedom of action in space.” As the space domain is contested, it is necessary for developers, manufacturers, owners, and operators of space systems to design, build, operate, and manage them so that they are resilient to cyber incidents and radio-frequency spectrum interference. Space Policy Directive-3 (SPD-3) of June 18, 2018 (National Space Traffic Management Policy), states that “[s]atellite and constellation owners should participate in a pre-launch certification process” that should consider a number of factors, including encryption of satellite command and control links and data protection measures for ground site operations. The National Cyber Strategy of September 2018 states that my Administration will enhance efforts to protect our space assets and supporting infrastructure ( printed page 56156) from evolving cyber threats, and will work with industry and international partners to strengthen the cyber resilience of existing and future space systems. Sec. 2 . Definitions. For the purposes of this memorandum, the following definitions shall apply: (a) “Space System” means a combination of systems, to include ground systems, sensor networks, and one or more space vehicles, that provides a space-based service. A space system typically has three segments: a ground control network, a space vehicle, and a user or mission network. These systems include Government national security space systems, Government civil space systems, and private space systems. (b) “Space Vehicle” means the portion of a space system that operates in space. Examples include satellites, space stations, launch vehicles, launch vehicle upper stage components, and spacecraft. (c) “Positive Control” means the assurance that a space vehicle will only execute commands transmitted by an authorized source and that those commands are executed in the proper order and at the intended time. (d) “Critical space vehicle functions (critical functions)” means the functions of the vehicle that the operator must maintain to ensure intended operations, positive control, and retention of custody. The failure or compromise of critical space vehicle functions could result in the space vehicle not responding to authorized commands, loss of critical capability, or responding to unauthorized commands. Sec. 3 . Policy. Cybersecurity principles

The excerpt is reproduced from the public federal record and may omit later sections, tables, signatures or attachments. Open the official source for the complete text.

Questions for accountability

How to use this page

This is a source-record entry, not a truth-rating by itself. It preserves the action, date and original government publication so it can be connected to later claims, implementation records, court decisions, costs and measurable outcomes. Editorial claim reviews on this site use separate finding labels and explain the evidence for those findings.

Open primary source ↗