NASA Best Practices Guide for Mission Cybersecurity
GR-DEVA-01

Computing Device Authentication Function

Parent: GR

Description

The mission should provide the capability to uniquely identify and authenticate all types of computing devices, including mobile devices and network connected endpoint devices (including workstations, printers, servers, VoIP Phones, VTC CODECs) before establishing a network connection.

Mapped SPARTA techniques

2 techniques

  • IA-0008.01Rogue Ground StationST0003
    addresses
    moderate

    Device authentication governs equipment attaching to mission networks, which narrows a rogue ground station operating inside the mission's own infrastructure but not one transmitting from outside it, where MI-AUTH-02 carries the interdiction.

  • IA-0011Auxiliary Device CompromiseST0003
    addresses
    moderate

    The practice requires that all types of computing devices be uniquely identified and authenticated, which is the check an unauthorised peripheral or removable device fails. [Curation] The excerpt scopes device authentication to network-connected endpoint devices before establishing a NETWORK CONNECTION. IA-0011 covers peripherals and removable media over USB, UART and SpaceWire, which are not network connections and are not authenticated by this practice. The network-attached subset is covered, the dominant scope is not.

Cite as SafeMode Space, nasa-bpg GR-DEVA-01.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.