NASA Best Practices Guide for Mission Cybersecurity
GR-MON-04

Threat Activity Response & Reporting Function

Parent: GR

Description

The mission should develop parameters to describe normal activities on the network for accessing and controlling mission applications and capabilities in a manner that allows security operations incident response and leadership to make effective decisions about resource allocation and risk management.

Mapped SPARTA techniques

2 techniques

  • DE-0010Overflow Audit LogST0006
    addresses
    moderate

    The practice requires parameters describing normal network activity for accessing and controlling mission applications. Overflowing the audit log is an abnormality against that baseline, though the practice governs the baseline rather than protecting the log.

  • Malicious commanding through a valid ground station authenticates correctly, so a baseline of normal commanding activity is one of the few controls that can surface it. The practice's parameters are that baseline, which is active detection against the technique's defining vector.

Cite as SafeMode Space, nasa-bpg GR-MON-04.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.