NASA Best Practices Guide for Mission Cybersecurity
GR-MON-03

Network and Communications Monitoring Function

Parent: GR

Description

The mission should provide the capability for each system owner to monitor communications at the external boundary of the system and at mission critical internal boundaries within the system.

Mapped SPARTA techniques

4 techniques

  • EXF-0003Signal InterceptionST0008
    addresses
    moderate

    Signal interception is passive: a tapped ground LAN or an intercepted space link produces no traffic for boundary monitoring to observe. The practice governs the network whose taps the technique exploits without detecting the tap.

  • EXF-0007Compromised Ground SystemST0008
    mitigates
    moderate

    Siphoning mission data from a foothold in ground infrastructure crosses the external boundary the practice requires be monitored, and boundary monitoring at mission-critical internal points is active detection of the exfiltration.

  • EXF-0008Compromised Developer SiteST0008
    mitigates
    moderate

    A breached development or integration environment exfiltrates source, test vectors, and build artifacts across a monitored boundary, which is the detection point the practice mandates.

  • EXF-0009Compromised Partner SiteST0008
    addresses
    moderate

    A partner site sits outside the mission's own boundary, so the practice detects the traffic crossing into mission systems but not collection occurring wholly within the third party.

Cross-framework references

Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.

Crosswalks to 1 in NIST SP 800-53 Rev. 5

Cite as SafeMode Space, nasa-bpg GR-MON-03.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.