NASA Best Practices Guide for Mission Cybersecurity
MI-SOFT-02

Software and Hardware Testing Function

Parent: MI

Description

The mission should establish procedures and technical methods to perform end to end testing to include negative testing (i.e., abuse cases) of the mission hardware and software as it would be in an operating state (test as you fly).

Mapped SPARTA techniques

6 techniques

  • The parent hardware and firmware corruption technique spans induced corruption as well as latent defect. Testing addresses the latent half only.

  • EX-0005.01Design FlawsST0004
    mitigates
    moderate

    Design flaws in hardware and firmware are what end-to-end negative testing in an as-flown configuration is meant to surface before launch, which is the practice's explicit test-as-you-fly requirement.

  • Malicious use of legitimate hardware commands is a behaviour an abuse-case test campaign would exercise, but the commands are by design valid, so testing documents the exposure rather than removing it.

  • EX-0009Exploit Code FlawsST0004
    addresses
    moderate

    Negative testing finds a subset of exploitable code flaws, and the as-flown requirement catches the integration-specific ones assurance review misses. It does not reach the class of defect only discoverable by analysis, so this is addresses while MI-SOFT-01 carries the mitigates.

  • EX-0013FloodingST0004
    addresses
    moderate

    Flooding is an abuse case in the practice's sense, and as-flown testing is where saturation behaviour becomes visible; the practice does not provide the rate limiting that would interdict it.

  • EX-0013.02Erroneous InputST0004
    mitigates
    moderate

    Erroneous input is the textbook abuse case, and negative testing is the named method. The practice interdicts by finding the handling defect the technique relies on.

Cite as SafeMode Space, nasa-bpg MI-SOFT-02.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.