5
(ii)
Physical protection measures designed to reduce
the vulnerabilities of a space vehicle's command,
control, and telemetry receiver systems;
(iii) Protection against communications jamming and
spoofing, such as signal strength monitoring programs,
secured transmitters and receivers, authentication, or
effective, validated, and tested encryption measures
designed to provide security against existing and
anticipated threats during the entire mission
lifetime;
(iv)
Protection of ground systems, operational
technology, and information processing systems through
the adoption of deliberate cybersecurity best
practices. This adoption should include practices
aligned with the National Institute of Standards and
Technology's Cybersecurity Framework to reduce the
risk of malware infection and malicious access to
systems, including from insider threats. Such
practices include logical or physical segregation;
regular patching; physical security; restrictions on
the utilization of portable media; the use of
antivirus software; and promoting staff awareness and
training inclusive of insider threat mitigation
precautions;
(v)
Adoption of appropriate cybersecurity hygiene
practices, physical security for automated information
systems, and intrusion detection methodologies for
system elements such as information systems, antennas,
terminals, receivers, routers, associated local and
wide area networks, and power supplies; and
(vi)
Management of supply chain risks that affect
cybersecurity of space systems through tracking
manufactured products; requiring sourcing from trusted
suppliers; identifying counterfeit, fraudulent, and
malicious equipment; and assessing other available
risk mitigation measures.
(c) Implementation of these principles, through rules,
regulations, and guidance, should enhance space system
cybersecurity, including through the consideration and adoption,
where appropriate, of cybersecurity best practices and norms of
behavior.