NASA Best Practices Guide for Mission Cybersecurity
GR-AUTH-03

Secure Workload-to-Workload Authenticator Function

Parent: GR

Description

The mission should define policy and procedures to ensure that the developed or delivered systems do not embed unencrypted static authenticators in applications, access scripts, configuration files, nor store unencrypted static authenticators on function keys.

Mapped SPARTA techniques

3 techniques

  • RD-0003.02Cryptographic KeysST0002
    addresses
    moderate

    The practice forbids embedding unencrypted static authenticators in delivered systems, which removes the most direct route by which an adversary obtains cryptographic keys from a fielded artifact. [Curation] RD-0003.02 is the adversary obtaining cryptographic keys by any means, including theft from personnel, cryptanalysis, and insider access. Forbidding embedded static authenticators closes one acquisition route out of many, and the corpus rule against mitigates on resource-development techniques applies.

  • Reconnaissance of cryptographic algorithms is a different objective from harvesting an embedded key, but the two share the artifact: a delivered image that carries neither an embedded authenticator nor the configuration around it yields less to inspection. Recorded at low confidence because the excerpt is about authenticators rather than algorithm disclosure.

  • REC-0003.04Valid CredentialsST0001
    addresses
    moderate

    Harvesting credentials from scripts and configuration files is precisely what a prohibition on embedded static authenticators interdicts. [Curation] The closest of the three reconnaissance calls, since a prohibition on embedded static authenticators genuinely removes a location credentials are harvested from. It is still a reconnaissance technique whose scope covers credential gathering by every other route, and the corpus rule against mitigates on reconnaissance holds, so addresses.

Cite as SafeMode Space, nasa-bpg GR-AUTH-03.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.