Statement
Space-sector guidance and protocol-security reports, operational-technology, software-supply-chain, zero-trust, post-quantum, and cyber-resilience standards provide relevant but fragmented reference points; their existence does not establish integration or assurance.
Evidence dimensions
- Basis
- observed
- Readiness
- major scale up
- Confidence
- strong
Assessment rationale
Authoritative publications separately address OT security, zero trust, cyber-resilient systems, secure development, supply chains, and post-quantum cryptography. NASA's BPG is guidance, CCSDS 350.0-G-3 is an informational report, and the CryptoLib record is an abstract-only implementation report. Their different authorities, scopes, assumptions, and system boundaries support the claim that reference points exist but do not by themselves establish compatibility, integration, conformance, or assurance for a closed habitat.
Citations and locators
- Guide to Operational Technology Security (opens external site in a new tab)
Sections 2 and 3 on operational-technology architectures, safety and availability constraints, threats, and risk differences from ordinary information systems. · direct normative authority - Zero Trust Architecture (opens external site in a new tab)
Sections 2 and 3 on zero-trust tenets and logical components, and section 7 on threats; enterprise scope is explicit. · scope boundary - Secure Software Development Framework (SSDF) Version 1.1 (opens external site in a new tab)
Table 1 practices PO, PS, PW, and RV for secure software development and vulnerability response. · direct normative authority - Module-Lattice-Based Key-Encapsulation Mechanism Standard (opens external site in a new tab)
Sections 1 through 7 defining ML-KEM purpose, parameter sets, algorithms, and implementation requirements. · direct normative authority - Space System Protection Standard (opens external site in a new tab)
Active NASA mission-protection requirements; applicability does not establish implementation or assurance for any particular architecture. · direct normative authority - Space Security: Best Practices Guide (opens external site in a new tab)
Sections 1.1–1.2 and the principles/control mappings: NASA describes mission-security guidance and an initial starting point, not a validated integrated architecture. · direct observation - The Application of Security to CCSDS Protocols (opens external site in a new tab)
Foreword, document status, and Section 1 purpose and scope: protocol-layer security options classified as a Green Book informational report, not a Recommended Standard. · scope boundary - The State of CryptoLib – The Open-Source Satellite Cryptography Library (opens external site in a new tab)
NTRS abstract paragraphs 2–4: the project aims at CCSDS SDLS compliance and reports selected TC, TM, and AOS cryptography functions; the source is abstract-only and reports development status rather than conformance. · direct observation
Assumptions and limits
The assessment applies to this bounded statement and the cited source scopes. A source can support one relationship without validating a generation ship, and an editorial grade does not substitute for independent review or representative demonstration.
What would change this conclusion?
A published, independently reviewed architecture that maps these standards into one representative closed-habitat assurance case, resolves conflicting assumptions, and passes integrated safety and recovery tests would change the fragmentation conclusion. Merely citing more standards would not.
Editorial record
- Prepared by: GShips Project
- Last reviewed: 2026-07-26
- Review status: substantive editorial review
- Reviewer: GShips Project editorial synthesis
- Independent review: pending two person required
- Conflicts: Publisher intends to explore a commercial venture based on some GShips work; no entity, funding, customer, sponsor, or partner relationship with cited organizations is reported.
- High-consequence domains: cybersecurity, spacecraft-safety, dual-use