Abstract
Satellite operations are critical to maintain satellite services and assets in nominal conditions. From their workstations operators, engineers, administrators and others manage literally millions of US$ in assets and maintain services whose availability is of utmost important in our modern society. The increase of the cyber threat has forced the introduction of several cybersecurity controls within the operational infrastructure such as network security, cybersecurity monitoring, security engineering, source code security audits, etc. However, one field which is yet to be addressed in most organizations is accountability. The definition of accountability according to the ISO 27000 standard in Information Security is: “Responsibility of an entity for its actions and decisions”. Accountability is therefore closely linked with authentication and traceability as without a proper authentication and traceability the accountability cannot be provided. Accountability is an essential cybersecurity measure. In addition to being a deterrent factor for internal attacks, it is also a crucial element in the identification, containment and reaction to internal and external cyberattacks. The implementation of accountability measures within the operational infrastructure increases the visibility of security events; facilitates investigation because actions can be easily traced to accounts which might have been compromised as a result of the cyberattack or in the source of the cyberattack; permits a faster containment by blocking compromised accounts and speeds up reaction time by permitting an easier tracking of the attack traces. Finally, accountability measures generate sound forensic evidences which are required in case the attack arrives to court. Considering the importance of accountability measures as described in the previous paragraph, it might strike the reader why it has not yet been implemented in the operational infrastructure of most space organizations. The answer is simple: the traditional accountability approach in the IT world (i.e. individual accounts and strong password policies) is simply not implementable in most space operations. At the core of the explanation is the strong focus in availability that drives space operations for obvious reasons. With that in mind, shared common accounts valid for most (if not all) systems within a mission, simple to remember passwords known by most of the team, lack of a central account management solution which would have allowed the implementation of a password management policy or even a simple registration of users and other accountability killer elements can be more easily understood. Newer missions are starting to consider limited accountability measures, but the introduction is still slow due to users resistance caused by the increase of complexity in terms of operational procedures, maintenance, etc. The paper will analyze the different entry points to operational equipment and for each of these entry points present existing technical solutions which can be easily implemented to significantly improve the accountability within space operations. Recommended implementation approaches will also be described together with the advantages and drawbacks for each option.
Cite
CITATION STYLE
Abanades, J. A., Vivero, J., & Martínez, M. (2018). Introducing accountability in space operations. In 15th International Conference on Space Operations, 2018. American Institute of Aeronautics and Astronautics Inc, AIAA. https://doi.org/10.2514/6.2018-2480
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.