NASA Best Practices Guide for Mission Cybersecurity
MI-MA-01

Mission Recovery Function

Parent: MI

Description

The mission should include intentional disruptions consistent with the mission vulnerability analysis in anomaly detection, response, and recovery plans and designs in the flight segment and ground segment.

Mapped SPARTA techniques

7 techniques

  • EX-0010.01RansomwareST0004
    addresses
    moderate

    Ransomware produces a denial the recovery plan must handle, and recovery from a known-good state is what makes the extortion fail. The practice governs the response without addressing the intrusion.

  • EX-0010.02Wiper MalwareST0004
    addresses
    moderate

    Wiper malware is a destructive disruption whose remedy is planned recovery. Same governance relationship as ransomware.

  • Deception is an integrity effect rather than a disruption, so the practice's anomaly-detection arm governs it while its recovery arm, written for disruptions, does not reach it.

  • IMP-0002DisruptionST0009
    mitigates
    moderate

    The practice requires that intentional disruptions be carried into anomaly detection, response, and recovery plans across both segments. Disruption is the named case, and planned recovery is active recovery against it, which meets the mitigates bar.

  • IMP-0003DenialST0009
    mitigates
    moderate

    Denial of mission service is an intentional disruption in the practice's own terms, and recovery planning is the response the practice mandates.

  • IMP-0004DegradationST0009
    mitigates
    moderate

    Degradation is the partial case of the same effect and is covered by the same planning obligation.

  • IMP-0005DestructionST0009
    addresses
    moderate

    Destruction is deliberately typed below its sibling impact techniques: recovery planning cannot restore a destroyed vehicle, so the practice governs the mission's preparation for the loss rather than recovering from the technique.

Cite as SafeMode Space, nasa-bpg MI-MA-01.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.