NASA Best Practices Guide for Mission Cybersecurity
MI-ARCH-01

Mission Least Privilege Function

Parent: MI

Description

The mission should establish and maintain a current and accurate data flow diagram covering mission essential data flows, including those that pass through mission-external service providers.

Mapped SPARTA techniques

6 techniques

  • Co-opting a secondary link as a covert data path succeeds where that link is absent from the mission's own picture of its flows. Maintaining the diagram is the governance answer.

  • EXF-0009Compromised Partner SiteST0008
    addresses
    moderate

    The practice requires a current and accurate data-flow diagram covering mission essential flows including those passing through mission-external service providers, which is precisely the visibility a compromised partner site exploits the absence of. It is a discovery and inventory obligation, so it governs rather than interdicts. Note that this practice's title reads as least privilege while its description is data-flow mapping; the mapping follows the description.

  • A payload communication channel that routes host-bus data to customer networks is exactly the undocumented flow the diagram obligation exists to make visible.

  • IA-0009Trusted RelationshipST0003
    addresses
    moderate

    Trusted relationships are the mission-external dependencies the data-flow diagram is required to cover. Knowing the flow is the precondition for governing the trust; the practice does not itself constrain it.

  • IA-0009.02VendorST0003
    addresses
    moderate

    A vendor connection is a mission-external service provider flow the diagram must include, which is what makes an unexpected path through it visible.

  • IA-0009.03User SegmentST0003
    addresses
    moderate

    The user segment is a mission-external flow in the same sense, and the diagram obligation is what surfaces its reach back into mission systems.

Cite as SafeMode Space, nasa-bpg MI-ARCH-01.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.