NASA Best Practices Guide for Mission Cybersecurity
MI-SOFT-01

Software Mission Assurance Function

Parent: MI

Description

The mission should perform software assurance via established procedures and technical methods.

Mapped SPARTA techniques

4 techniques

  • EX-0009Exploit Code FlawsST0004
    addresses
    moderate

    Exploiting defects in software running on the vehicle is what software assurance is for: established procedures and technical methods are what remove the defect class before flight. Moderate rather than high because the practice states the obligation without naming the methods, and assurance reduces rather than eliminates defect density. [Curation] Software assurance removes defects from code the mission develops. The EX-0009 parent spans libraries, drivers and supporting services the mission procures rather than writes, so assurance covers a real but non-dominant part of the technique's scope. The mitigates is kept on EX-0009.01 Flight Software, which is the mission-developed member of the family.

  • EX-0009.01Flight SoftwareST0004
    mitigates
    moderate

    Flight software is the mission-developed code that software assurance directly covers, which makes this the strongest member of the EX-0009 family for this practice.

  • EX-0009.02Operating SystemST0004
    addresses
    moderate

    The on-board operating system is typically procured rather than developed, so mission software assurance governs its selection and integration without covering its internals.

  • A known defect in a COTS or FOSS component is closed by patching and component inventory, not by assurance of mission-developed code. The practice governs the mission's knowledge of its composition without interdicting the technique.

Cite as SafeMode Space, nasa-bpg MI-SOFT-01.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.