{
  "schemaVersion": "gships-review-packet-1",
  "packetId": "systems:cybersecurity",
  "stableId": "cybersecurity",
  "family": "systems",
  "slug": "cybersecurity",
  "title": "Cybersecurity, software assurance & recovery",
  "status": "prepared-human-review-not-started",
  "release": {
    "releaseId": "public-alpha-2026-07-26-research-visuals-r14",
    "sourceCommit": "3eb036fce3d711336c8c605625895e8a2e799ab0",
    "corpusGeneratedAt": "2026-07-25",
    "frozenAt": "2026-07-26T22:50:50.000Z",
    "canonicalOrigin": "https://gships.dammonburden.com"
  },
  "paths": {
    "human": "/review/systems/cybersecurity",
    "family": "/review/systems",
    "packet": "/review-packets/systems/cybersecurity.c143c856d4978f82.json",
    "decisionTemplate": "/review-packets/systems/cybersecurity.c143c856d4978f82.decision-template.json",
    "worksheet": "/review-packets/systems/cybersecurity.c143c856d4978f82.worksheet.md",
    "byFingerprint": "/review-packets/by-fingerprint/c143c856d4978f824701c6831dcc968482b4215f700f53579ca3d4d6155f9b0d.json"
  },
  "boundary": "Prepared review packet; human review has not started. This packet is not a completed review, endorsement, reviewer appointment, partnership, or authorization to act.",
  "governingPolicies": [
    {
      "id": "policy-editorial-governance-001",
      "version": "0.1.0",
      "path": "/editorial-policy",
      "recordType": "governing-policy",
      "fingerprint": "1f6a1f823e8bfe891b6a707c5dce2ee2337c0bb7d915b48d6060ca82b8da1b47",
      "snapshot": {
        "id": "policy-editorial-governance-001",
        "version": "0.1.0",
        "status": "foundation-policy-controls-not-yet-staffed",
        "adoptedForFoundation": "2026-07-25",
        "title": "Editorial governance and independent review",
        "publisher": "GShips Project",
        "maintainer": "Dammon Burden",
        "publisherInterest": "The maintainer intends to explore a commercial venture based on some GShips work. No entity, outside funding, customer, sponsor, or indexed-organization relationship currently exists.",
        "currentBoundary": "No independent domain reviewer or review council is currently appointed. Foundation records and outlines may not be represented as independently reviewed.",
        "reviewerSelection": [
          "Publish the reviewer’s name, relevant credentials or lived expertise, review scope, compensation status, and declared conflicts with consent.",
          "Select for the actual claim domain rather than general prestige; include affected-community and disability-led expertise where rights or access are involved.",
          "Do not treat an employee, investor, customer, sponsor, source author, or directly supervised collaborator as independent for the affected claim."
        ],
        "reviewProcess": [
          "Provide the exact claim, sources, locators, assumptions, counterevidence, transfer limits, and proposed evidence dimensions.",
          "Record approve, revise, contest, or reject at claim level; silence and event attendance never count as review.",
          "Publish material minority findings and the editor’s reasoned response.",
          "High-consequence medical, reproductive, nuclear, radiation, cybersecurity, governance, and dual-use claims require two qualified independent reviewers with complementary scopes.",
          "A reviewer may recuse at any time; unresolved conflicts or missing expertise block the reviewed label."
        ],
        "appealAndCorrection": [
          "A correction receives a reference identifier and triage record; safety-critical allegations receive priority.",
          "A material editorial decision may be appealed to a reviewer not involved in the original decision once such a panel exists.",
          "Substantive reversals, unresolved disputes, and removed conclusions receive a dated public record that protects reporter privacy.",
          "No sponsor, customer, founder, or reviewer may purchase, suppress, or unilaterally assign an evidence grade."
        ],
        "publicationGate": "Public 1.0 requires named review coverage across every Academy track, documented high-consequence two-person review, a material-corrections log, reviewer conflict records, and an operating appeal path.",
        "correctionPath": "/corrections"
      }
    },
    {
      "id": "policy-dual-use-001",
      "version": "0.1.0",
      "path": "/dual-use",
      "recordType": "governing-policy",
      "fingerprint": "81637e2849f9c0866d23f7174eb9a2ce522b86313167ebf5022fca122d6e506c",
      "snapshot": {
        "id": "policy-dual-use-001",
        "version": "0.1.0",
        "status": "planned-controls-not-yet-operational",
        "adoptedForFoundation": "2026-07-25",
        "title": "Civil, defensive, and rights-preserving use boundary",
        "summary": "GShips may research safety, resilience, logistics, communications, recovery, and cyber defense only within explicit end-use, rights, and independent-review controls. Calling an activity defensive is never sufficient by itself.",
        "scopeTrigger": "Apply dual-use review before accepting or materially advancing customer, funder, collaborator, operational, procurement, or publication-sensitive work whose capability, data, end use, or transfer could reasonably enable a prohibited use. Public non-actionable education still follows prohibited-content and sensitive-publication controls.",
        "allowedInPrinciple": [
          "Safety engineering and independently assessed protection",
          "Resilience, graceful degradation, recovery, and disaster response",
          "Civil logistics, maintenance, communications, and knowledge continuity",
          "Cyber defense, secure software, incident response, and recovery",
          "Rights-preserving health, accessibility, ecology, education, and governance research"
        ],
        "prohibited": [
          "Identification, tracking, prioritization, or engagement of people or assets for force, weapons, repression, or offensive operations; safety navigation, astronomy, collision avoidance, search and rescue, and independently governed planetary defense are not prohibited by this clause",
          "Weapons command-and-control or targeting support",
          "Offensive access, persistence, exploitation, or destructive cyber payloads",
          "Mass surveillance, biometric repression, or political-control systems",
          "Autonomous force application",
          "Coercive reproductive, medical, genetic, disability, or civic control",
          "Nonconsensual experimentation or treating residents as research instruments"
        ],
        "reviewRequiredBeforeAnyRelevantWork": [
          "Customer, funder, collaborator, jurisdiction, beneficial-owner, and end-use screening",
          "Export-control and sanctions review by qualified counsel when applicable",
          "Written scope, allowed-use, prohibited-use, audit, termination, and incident clauses",
          "Independent stop-work authority with a named alternate and founder recusal",
          "Sensitive-publication and information-hazard review",
          "Whistleblowing, escalation, incident response, appeal, and anti-retaliation paths",
          "Aggregate transparency reporting that protects legitimate privacy and security"
        ],
        "currentBoundary": "No screening body, independent stop-work authority, contractual controls, or appeal body currently exists. Therefore no relevant customer, defense, dual-use, or operational engagement is authorized by this policy.",
        "changeControl": "Material changes require a dated public rationale, independent review, and may not be approved by the founder alone.",
        "correctionPath": "/corrections"
      }
    }
  ],
  "reviewContract": {
    "questions": [
      {
        "id": "question-1",
        "text": "Does each evidence basis, readiness level, confidence level, rationale, and locator match the frozen sources?",
        "required": true
      },
      {
        "id": "question-2",
        "text": "Are dependencies, failure modes, precursors, unknowns, Earthside benefits, and the stop gate technically and ethically bounded?",
        "required": true
      },
      {
        "id": "question-3",
        "text": "Which conclusion should be approved, revised, contested, rejected, or recused from at its current fingerprint?",
        "required": true
      }
    ],
    "exclusions": [
      "A system packet is not a complete spacecraft design, feasibility proof, safety case, or launch authorization.",
      "Context sources do not become direct support unless the record says so with an exact locator and relation."
    ],
    "requestedScopeCodes": [
      "defensive-cyber-safety",
      "information-science",
      "security-assurance",
      "systems-engineering"
    ],
    "dispositions": [
      "approve",
      "revise",
      "contest",
      "reject",
      "recuse"
    ],
    "prohibitedInputs": [
      "private legal names or contact details",
      "identity documents or raw credential files",
      "accessibility or medical records",
      "confidential conflict evidence",
      "classified, export-controlled, proprietary, or exploit material"
    ],
    "freshness": {
      "maximumDecisionAgeFromFreezeDays": 365,
      "eventOccurrenceRule": "Not applicable to this packet family."
    },
    "completionRule": "Every primary record must receive the required number of valid, current-fingerprint approvals; every complementary scope group and required domain must be covered; any unresolved revise, contest, or reject disposition blocks publication.",
    "highConsequenceRule": "Named medical, reproductive, nuclear, radiation, cybersecurity, governance, and dual-use conclusions require two distinct qualified independent humans covering complementary domain-method and rights/public-interest scopes."
  },
  "primaryRecords": [
    {
      "recordType": "system",
      "recordId": "cybersecurity",
      "title": "Cybersecurity, software assurance & recovery",
      "publicPath": "/systems/cybersecurity",
      "recordFingerprint": "48a0199de1d45db9fdb9aad2b20fcd4d219be2d336a58c2b4b44921d27a82a21",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "defensive-cyber-safety",
              "security-assurance"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "slug": "cybersecurity",
        "name": "Cybersecurity, software assurance & recovery",
        "shortName": "Cyber resilience",
        "index": 12,
        "thesis": "Generation-ship security protects a civilization’s ability to operate, repair, govern, learn, and recover without an external rescuer—not merely its secrets.",
        "currentState": [
          "Space, operational-technology, software-supply-chain, zero-trust, post-quantum, and cyber-resilience standards provide relevant but fragmented reference points; their existence does not establish integration or assurance.",
          "Secure-update patterns, attestation, delay-tolerant networking, formally assessed kernels, software bills of materials, and reproducible-build practices exist in different contexts. Availability does not establish compatibility, flight qualification, century maintenance, or safe integration.",
          "Within the public sources sampled for this foundation draft, we did not identify a generation-ship cybersecurity standard or a demonstrated century-scale cryptographic deployment."
        ],
        "unknowns": [
          "Trust anchors, identity, secure time, revocation, incident command, threshold recovery, crypto-agile migration, anti-rollback, and archival signature interpretation must work locally after permanent loss of Earth.",
          "Insiders, collusion, governance capture, compromised suppliers, corrupted hardware, malicious maintenance, radiation faults, operator error, and generational loss of expertise must be addressed without turning safety monitoring into surveillance or political control.",
          "Onboard manufacturing makes malicious designs, poisoned toolchains, compromised metrology, counterfeit replacement parts, and configuration drift cyber-physical threats."
        ],
        "earthBenefits": [
          "Disconnected trust fabrics, update airlocks, recovery vaults, and cyber ranges benefit critical infrastructure and remote industry.",
          "Crypto agility and toolchain escrow reduce obsolescence risk in medical, energy, transport, and public systems."
        ],
        "dependencies": [
          "ai-autonomy",
          "communications-navigation",
          "manufacturing-isru"
        ],
        "gate": "Mixed crews must repeatedly isolate a compromised zone, maintain life support, investigate locally, rebuild from known-good material, and rejoin safely.",
        "sources": [
          {
            "title": "NIST Cybersecurity Framework 2.0",
            "url": "https://www.nist.gov/cyberframework",
            "kind": "Primary or institutional source"
          },
          {
            "title": "NIST Cyber-Resilient Systems Engineering",
            "url": "https://csrc.nist.gov/pubs/sp/800/160/v2/r1/final",
            "kind": "Primary or institutional source"
          },
          {
            "title": "NIST Operational Technology Security",
            "url": "https://csrc.nist.gov/pubs/sp/800/82/r3/final",
            "kind": "Primary or institutional source"
          },
          {
            "title": "NIST Secure Software Development Framework",
            "url": "https://csrc.nist.gov/pubs/sp/800/218/final",
            "kind": "Primary or institutional source"
          }
        ],
        "failureModes": [
          "A compromised build, spare, model, credential, or maintenance interface crosses isolation boundaries.",
          "Cryptography, identity, or recovery procedures become obsolete while privileged operators lose the ability to re-establish trust."
        ],
        "precursors": [
          "Secure-by-design operational technology, reproducible builds, signed evidence graphs, and offline recovery media.",
          "Long-horizon incident exercises that include insider risk, degraded communications, hardware loss, and cryptographic migration."
        ]
      }
    },
    {
      "recordType": "claim",
      "recordId": "claim-12-01",
      "title": "Generation-ship security protects a civilization’s ability to operate, repair, govern, learn, and recover without an external rescuer—not merely its secrets.",
      "publicPath": "/claims/claim-12-01",
      "recordFingerprint": "908842da73f03771a9e09cc29bdc8e3863610f7ab9de665f452f153f7bb618b1",
      "reviewRequirements": {
        "minimumIndependentApprovals": 2,
        "highConsequenceDomains": [
          "cybersecurity",
          "governance",
          "life-support-continuity"
        ],
        "requiredDomainCodes": [
          "defensive-cyber-safety",
          "governance-law-rights"
        ],
        "requiredComplementaryScopeGroups": [
          {
            "id": "domain-method",
            "scopeClass": "domain-method",
            "oneOf": [
              "defensive-cyber-safety",
              "governance-law-rights",
              "security-assurance"
            ]
          },
          {
            "id": "rights-public-interest",
            "scopeClass": "rights-public-interest",
            "oneOf": [
              "affected-public-rights"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [
        "src-cr-nasa-space-security-bpg-revb",
        "src-cr-nist-cyber-resilience-800160v2r1",
        "src-cr-nist-incident-80061r3",
        "src-im-nist-ot-80082r3"
      ],
      "snapshot": {
        "id": "claim-12-01",
        "systemSlug": "cybersecurity",
        "kind": "thesis",
        "statementRef": {
          "field": "thesis"
        },
        "statement": "Generation-ship security protects a civilization’s ability to operate, repair, govern, learn, and recover without an external rescuer—not merely its secrets.",
        "statementFingerprint": "c805232b478356847ba74782b6221b09ce6a1bc05c761188d34e892a9ddb771c",
        "assessment": {
          "status": "editorial-assessed",
          "basis": "normative",
          "readiness": "early-research",
          "confidence": "strong",
          "rationale": "Current cyber-resiliency and incident-response guidance explicitly centers mission or organizational outcomes, anticipation, continued operation, recovery, and adaptation. NASA's Space Security Best Practices Guide strengthens the present space-mission context but does not support the claim's civilization-scale governance, learning, repair, or permanent-isolation extension. Extending the framing remains a normative systems proposal, not a demonstrated generation-ship implementation."
        },
        "citations": [
          {
            "sourceId": "src-cr-nist-cyber-resilience-800160v2r1",
            "locator": "Executive summary and sections 2.1 through 2.3 defining cyber resiliency as the ability to anticipate, withstand, recover from, and adapt to adverse conditions involving cyber resources.",
            "relation": "direct-method"
          },
          {
            "sourceId": "src-cr-nist-incident-80061r3",
            "locator": "CSF 2.0 Community Profile across Govern, Identify, Protect, Detect, Respond, and Recover, including preparation and improvement outside the immediate response phase.",
            "relation": "direct-normative-authority"
          },
          {
            "sourceId": "src-im-nist-ot-80082r3",
            "locator": "Sections 2, 3, 5, and 6 on OT mission, safety, reliability, availability, physical effects, incident response, and recovery constraints.",
            "relation": "scope-boundary"
          },
          {
            "sourceId": "src-cr-nasa-space-security-bpg-revb",
            "locator": "Sections 1.1–1.2 on risk-based mission-success framing, space-vehicle and ground-segment scope, initial-baseline status, and the statement that the guide does not replace the System Security Plan.",
            "relation": "scope-boundary"
          }
        ],
        "contextSourceIds": [
          "core-12-1",
          "core-12-2",
          "core-12-3",
          "core-12-4"
        ],
        "editorialProvenance": {
          "status": "substantive-editorial-review",
          "reviewers": [
            "GShips Project editorial synthesis"
          ],
          "conflicts": [
            "Publisher intends to explore a commercial venture based on some GShips work; no entity, funding, customer, sponsor, or partner relationship with cited organizations is reported."
          ]
        },
        "whatWouldChange": "A reviewed alternative security objective that better preserves essential service, repair, learning, legitimate governance, and local recovery could replace this framing. Repeated closed-habitat tests showing that confidentiality-centered controls alone preserve those outcomes would weaken it; repeated failures of mission-centered designs would require narrowing or redesign.",
        "highConsequence": [
          "cybersecurity",
          "life-support-continuity",
          "governance"
        ]
      }
    },
    {
      "recordType": "claim",
      "recordId": "claim-12-02",
      "title": "Space-sector guidance and protocol-security reports, operational-technology, software-supply-chain, zero-trust, post-quantum, and cyber-resilience standards provide relevant but fragmented reference points; their existence does not establish integration or assurance.",
      "publicPath": "/claims/claim-12-02",
      "recordFingerprint": "0f49699074aad1bdc4026a7e08cecd517f96beb614fa4055762c508de9fa31fc",
      "reviewRequirements": {
        "minimumIndependentApprovals": 2,
        "highConsequenceDomains": [
          "cybersecurity",
          "dual-use",
          "spacecraft-safety"
        ],
        "requiredDomainCodes": [
          "defensive-cyber-safety",
          "dual-use-risk"
        ],
        "requiredComplementaryScopeGroups": [
          {
            "id": "domain-method",
            "scopeClass": "domain-method",
            "oneOf": [
              "defensive-cyber-safety",
              "dual-use-risk",
              "security-assurance"
            ]
          },
          {
            "id": "rights-public-interest",
            "scopeClass": "rights-public-interest",
            "oneOf": [
              "affected-public-rights"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [
        "src-cr-ccsds-350-0-g-3",
        "src-cr-nasa-cryptolib-2023",
        "src-cr-nasa-space-security-bpg-revb",
        "src-cr-nasa-std-1006a",
        "src-cr-nist-fips203-mlkem",
        "src-cr-nist-ssdf-800218",
        "src-cr-nist-zero-trust-800207",
        "src-im-nist-ot-80082r3"
      ],
      "snapshot": {
        "id": "claim-12-02",
        "systemSlug": "cybersecurity",
        "kind": "current state",
        "statementRef": {
          "field": "currentState",
          "index": 0
        },
        "statement": "Space-sector guidance and protocol-security reports, operational-technology, software-supply-chain, zero-trust, post-quantum, and cyber-resilience standards provide relevant but fragmented reference points; their existence does not establish integration or assurance.",
        "statementFingerprint": "dee7d9059c1d19cbe5f79d789f2e9c600c7a847341eebf8b9c2ad004a902cde2",
        "assessment": {
          "status": "editorial-assessed",
          "basis": "observed",
          "readiness": "major-scale-up",
          "confidence": "strong",
          "rationale": "Authoritative publications separately address OT security, zero trust, cyber-resilient systems, secure development, supply chains, and post-quantum cryptography. NASA's BPG is guidance, CCSDS 350.0-G-3 is an informational report, and the CryptoLib record is an abstract-only implementation report. Their different authorities, scopes, assumptions, and system boundaries support the claim that reference points exist but do not by themselves establish compatibility, integration, conformance, or assurance for a closed habitat."
        },
        "citations": [
          {
            "sourceId": "src-im-nist-ot-80082r3",
            "locator": "Sections 2 and 3 on operational-technology architectures, safety and availability constraints, threats, and risk differences from ordinary information systems.",
            "relation": "direct-normative-authority"
          },
          {
            "sourceId": "src-cr-nist-zero-trust-800207",
            "locator": "Sections 2 and 3 on zero-trust tenets and logical components, and section 7 on threats; enterprise scope is explicit.",
            "relation": "scope-boundary"
          },
          {
            "sourceId": "src-cr-nist-ssdf-800218",
            "locator": "Table 1 practices PO, PS, PW, and RV for secure software development and vulnerability response.",
            "relation": "direct-normative-authority"
          },
          {
            "sourceId": "src-cr-nist-fips203-mlkem",
            "locator": "Sections 1 through 7 defining ML-KEM purpose, parameter sets, algorithms, and implementation requirements.",
            "relation": "direct-normative-authority"
          },
          {
            "sourceId": "src-cr-nasa-std-1006a",
            "locator": "Active NASA mission-protection requirements; applicability does not establish implementation or assurance for any particular architecture.",
            "relation": "direct-normative-authority"
          },
          {
            "sourceId": "src-cr-nasa-space-security-bpg-revb",
            "locator": "Sections 1.1–1.2 and the principles/control mappings: NASA describes mission-security guidance and an initial starting point, not a validated integrated architecture.",
            "relation": "direct-observation"
          },
          {
            "sourceId": "src-cr-ccsds-350-0-g-3",
            "locator": "Foreword, document status, and Section 1 purpose and scope: protocol-layer security options classified as a Green Book informational report, not a Recommended Standard.",
            "relation": "scope-boundary"
          },
          {
            "sourceId": "src-cr-nasa-cryptolib-2023",
            "locator": "NTRS abstract paragraphs 2–4: the project aims at CCSDS SDLS compliance and reports selected TC, TM, and AOS cryptography functions; the source is abstract-only and reports development status rather than conformance.",
            "relation": "direct-observation"
          }
        ],
        "contextSourceIds": [
          "core-12-1",
          "core-12-2",
          "core-12-3",
          "core-12-4"
        ],
        "editorialProvenance": {
          "status": "substantive-editorial-review",
          "reviewers": [
            "GShips Project editorial synthesis"
          ],
          "conflicts": [
            "Publisher intends to explore a commercial venture based on some GShips work; no entity, funding, customer, sponsor, or partner relationship with cited organizations is reported."
          ]
        },
        "whatWouldChange": "A published, independently reviewed architecture that maps these standards into one representative closed-habitat assurance case, resolves conflicting assumptions, and passes integrated safety and recovery tests would change the fragmentation conclusion. Merely citing more standards would not.",
        "highConsequence": [
          "cybersecurity",
          "spacecraft-safety",
          "dual-use"
        ]
      }
    },
    {
      "recordType": "claim",
      "recordId": "claim-12-03",
      "title": "Secure firmware-update patterns, platform recovery, software-component inventories, bundle-layer security for disrupted networking, and a publicly described CCSDS-oriented space-data-link cryptography library exist in different contexts. Availability does not establish compatibility, conformance, flight qualification, safe integration, or century maintenance.",
      "publicPath": "/claims/claim-12-03",
      "recordFingerprint": "6055efdd9314736b322ecafce96268e59c3ddc2c7874b92f43b11b7494689e92",
      "reviewRequirements": {
        "minimumIndependentApprovals": 2,
        "highConsequenceDomains": [
          "cybersecurity",
          "dual-use",
          "software-supply-chain",
          "spacecraft-safety"
        ],
        "requiredDomainCodes": [
          "defensive-cyber-safety",
          "dual-use-risk"
        ],
        "requiredComplementaryScopeGroups": [
          {
            "id": "domain-method",
            "scopeClass": "domain-method",
            "oneOf": [
              "defensive-cyber-safety",
              "dual-use-risk",
              "security-assurance"
            ]
          },
          {
            "id": "rights-public-interest",
            "scopeClass": "rights-public-interest",
            "oneOf": [
              "affected-public-rights"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [
        "src-cr-ccsds-350-0-g-3",
        "src-cr-cisa-sbom",
        "src-cr-ietf-rfc9019-suit",
        "src-cr-nasa-cryptolib-2023",
        "src-cr-nist-firmware-800193",
        "src-cr-nist-ssdf-800218",
        "src-pn-ietf-bpsec"
      ],
      "snapshot": {
        "id": "claim-12-03",
        "systemSlug": "cybersecurity",
        "kind": "current state",
        "statementRef": {
          "field": "currentState",
          "index": 1
        },
        "statement": "Secure firmware-update patterns, platform recovery, software-component inventories, bundle-layer security for disrupted networking, and a publicly described CCSDS-oriented space-data-link cryptography library exist in different contexts. Availability does not establish compatibility, conformance, flight qualification, safe integration, or century maintenance.",
        "statementFingerprint": "f34f71c04e7de1ae413c8ffe6b8bdb1238a23f2ea53cf1e06528b94325e93c4d",
        "assessment": {
          "status": "editorial-assessed",
          "basis": "observed",
          "readiness": "early-research",
          "confidence": "supported",
          "rationale": "The cited sources establish secure-firmware-update architecture, platform protect-detect-recover mechanisms, software-component transparency, and bundle-layer security. The NTRS abstract publicly describes an actively developed CCSDS-oriented cryptography library but does not establish conformance, secure implementation, deployment, or flight qualification. The sources do not establish compatibility among components, safe key governance, integration, or century maintenance."
        },
        "citations": [
          {
            "sourceId": "src-cr-ietf-rfc9019-suit",
            "locator": "Sections 3 through 7 and 10 on update roles, authenticated manifests, target matching, sequence controls, dependencies, interruption, installation, and recovery.",
            "relation": "direct-normative-authority"
          },
          {
            "sourceId": "src-cr-nist-firmware-800193",
            "locator": "Sections 3 and 4 on roots of trust and mechanisms to protect, detect unauthorized change, and securely recover platform firmware and critical data.",
            "relation": "scope-boundary"
          },
          {
            "sourceId": "src-cr-nist-ssdf-800218",
            "locator": "Practices PS.1 through PS.3 and PW.4 through PW.9 on protecting code, verifying third-party components, review, testing, secure defaults, and release integrity.",
            "relation": "direct-normative-authority"
          },
          {
            "sourceId": "src-cr-cisa-sbom",
            "locator": "SBOM definition, ecosystem roles, use cases, and current minimum-elements materials.",
            "relation": "direct-observation"
          },
          {
            "sourceId": "src-pn-ietf-bpsec",
            "locator": "Sections defining integrity and confidentiality security blocks for Bundle Protocol in disrupted and delay-tolerant networks.",
            "relation": "direct-normative-authority"
          },
          {
            "sourceId": "src-cr-ccsds-350-0-g-3",
            "locator": "Section 1 and protocol-layer application discussion; the Green Book is an informational scope boundary, not proof that CryptoLib conforms.",
            "relation": "scope-boundary"
          },
          {
            "sourceId": "src-cr-nasa-cryptolib-2023",
            "locator": "Abstract paragraphs 2–4: active-development and aims-to-comply language plus selected TC, TM, and AOS scope; abstract-only record.",
            "relation": "direct-observation"
          }
        ],
        "contextSourceIds": [
          "core-12-1",
          "core-12-2",
          "core-12-3",
          "core-12-4"
        ],
        "editorialProvenance": {
          "status": "substantive-editorial-review",
          "reviewers": [
            "GShips Project editorial synthesis"
          ],
          "conflicts": [
            "Publisher intends to explore a commercial venture based on some GShips work; no entity, funding, customer, sponsor, or partner relationship with cited organizations is reported."
          ]
        },
        "whatWouldChange": "A representative integrated test combining secure update, platform recovery, disrupted networking, transparent software composition, space-data-link cryptography, old hardware, power interruption, key loss or compromise, and verified rollback would raise readiness. A public conformance result and operational deployment would strengthen the CryptoLib example. Evidence of incompatibility, unsafe recovery, unmaintainable cryptography, or correlated trust failure would narrow candidate architectures.",
        "highConsequence": [
          "cybersecurity",
          "software-supply-chain",
          "spacecraft-safety",
          "dual-use"
        ]
      }
    },
    {
      "recordType": "claim",
      "recordId": "claim-12-04",
      "title": "Within the public sources sampled for this foundation draft, we did not identify a generation-ship cybersecurity standard or a demonstrated century-scale cryptographic deployment.",
      "publicPath": "/claims/claim-12-04",
      "recordFingerprint": "1f2f998d50f9608459ee4d3da4ac355a5bf83f8c7d328e5d931ade7d5e4ec478",
      "reviewRequirements": {
        "minimumIndependentApprovals": 2,
        "highConsequenceDomains": [
          "cryptography",
          "cybersecurity",
          "spacecraft-safety"
        ],
        "requiredDomainCodes": [
          "defensive-cyber-safety"
        ],
        "requiredComplementaryScopeGroups": [
          {
            "id": "domain-method",
            "scopeClass": "domain-method",
            "oneOf": [
              "defensive-cyber-safety",
              "security-assurance"
            ]
          },
          {
            "id": "rights-public-interest",
            "scopeClass": "rights-public-interest",
            "oneOf": [
              "affected-public-rights"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [
        "src-cr-nist-crypto-agility-cswp39u1",
        "src-cr-nist-cyber-resilience-800160v2r1",
        "src-cr-nist-fips204-mldsa",
        "src-cr-nist-key-management-80057p1r5"
      ],
      "snapshot": {
        "id": "claim-12-04",
        "systemSlug": "cybersecurity",
        "kind": "current state",
        "statementRef": {
          "field": "currentState",
          "index": 2
        },
        "statement": "Within the public sources sampled for this foundation draft, we did not identify a generation-ship cybersecurity standard or a demonstrated century-scale cryptographic deployment.",
        "statementFingerprint": "3f1223a76b93a7df07fdda1de97e20db6cb6a61d43dbc77e993cd336bd4414fd",
        "assessment": {
          "status": "editorial-assessed",
          "basis": "observed",
          "readiness": "no-known-path",
          "confidence": "supported",
          "rationale": "The bounded official corpus contains current standards and guidance for cyber resilience, key management, algorithm transition, and post-quantum primitives, each scoped to present systems and transitions. It contains neither a generation-ship cybersecurity standard nor a demonstrated century-scale cryptographic deployment. This is a transparent bounded-corpus finding, not proof that no relevant document exists anywhere."
        },
        "citations": [
          {
            "sourceId": "src-cr-nist-cyber-resilience-800160v2r1",
            "locator": "Scope, executive summary, and chapters 2 and 3; general systems-security engineering context without a generation-ship profile.",
            "relation": "direct-observation"
          },
          {
            "sourceId": "src-cr-nist-key-management-80057p1r5",
            "locator": "Sections 5 through 8 on algorithms, key lifecycle, protection periods, compromise, backup, recovery, archival, and destruction.",
            "relation": "context-only"
          },
          {
            "sourceId": "src-cr-nist-crypto-agility-cswp39u1",
            "locator": "Definition, discovery and inventory, strategic planning, protocol and application transitions, operational mechanisms, trade-offs, and areas for further work.",
            "relation": "context-only"
          },
          {
            "sourceId": "src-cr-nist-fips204-mldsa",
            "locator": "Sections 1 through 7 defining ML-DSA, approved parameter sets, and implementation requirements; no century-deployment claim.",
            "relation": "scope-boundary"
          }
        ],
        "contextSourceIds": [
          "core-12-1",
          "core-12-2",
          "core-12-3",
          "core-12-4"
        ],
        "editorialProvenance": {
          "status": "substantive-editorial-review",
          "reviewers": [
            "GShips Project editorial synthesis"
          ],
          "conflicts": [
            "Publisher intends to explore a commercial venture based on some GShips work; no entity, funding, customer, sponsor, or partner relationship with cited organizations is reported."
          ]
        },
        "whatWouldChange": "Discovery of an authoritative generation-ship cybersecurity standard would falsify the first bounded finding. Independently audited cryptographic operation over a century, including algorithm migration, key succession, archival validation, old hardware, and compromise recovery, would change the second; a paper lifetime estimate would not.",
        "highConsequence": [
          "cybersecurity",
          "cryptography",
          "spacecraft-safety"
        ]
      }
    },
    {
      "recordType": "claim",
      "recordId": "claim-12-05",
      "title": "Trust anchors, identity, secure time, revocation, incident command, threshold recovery, crypto-agile migration, anti-rollback, and archival signature interpretation must work locally after permanent loss of Earth.",
      "publicPath": "/claims/claim-12-05",
      "recordFingerprint": "2811cbe867ae12c3b3d54f9da45439d26535ec4349f41ae4a7cb36eb37ea26a1",
      "reviewRequirements": {
        "minimumIndependentApprovals": 2,
        "highConsequenceDomains": [
          "cybersecurity",
          "governance"
        ],
        "requiredDomainCodes": [
          "defensive-cyber-safety",
          "governance-law-rights"
        ],
        "requiredComplementaryScopeGroups": [
          {
            "id": "domain-method",
            "scopeClass": "domain-method",
            "oneOf": [
              "defensive-cyber-safety",
              "governance-law-rights",
              "security-assurance"
            ]
          },
          {
            "id": "rights-public-interest",
            "scopeClass": "rights-public-interest",
            "oneOf": [
              "affected-public-rights"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [
        "src-pn-ccsds-oais",
        "src-pn-ietf-bpsec",
        "src-pn-jpl-dsac"
      ],
      "snapshot": {
        "id": "claim-12-05",
        "systemSlug": "cybersecurity",
        "kind": "unknown",
        "statementRef": {
          "field": "unknowns",
          "index": 0
        },
        "statement": "Trust anchors, identity, secure time, revocation, incident command, threshold recovery, crypto-agile migration, anti-rollback, and archival signature interpretation must work locally after permanent loss of Earth.",
        "statementFingerprint": "9889918cc748c4b0b6cfa5f73d5debe30ebb19f2d08bbaf210e1d531d9552e19",
        "assessment": {
          "status": "editorial-assessed",
          "basis": "normative",
          "readiness": "early-research",
          "confidence": "supported",
          "rationale": "Bundle security, archival standards, atomic clocks, and current operational security practices address parts of the requirement. No reviewed evidence demonstrates crypto-agile identity, secure-time, revocation, threshold recovery, anti-rollback, incident command, and archival interpretation as one locally recoverable multigenerational institution."
        },
        "citations": [
          {
            "sourceId": "src-pn-ietf-bpsec",
            "locator": "Security-block processing, integrity and confidentiality services, threat model, and key-management exclusions.",
            "relation": "direct-normative-authority"
          },
          {
            "sourceId": "src-pn-ccsds-oais",
            "locator": "Representation information, preservation planning, archive management, access, and designated-community requirements.",
            "relation": "direct-normative-authority"
          },
          {
            "sourceId": "src-pn-jpl-dsac",
            "locator": "Space atomic-clock stability result, mission duration, and bounded technology-demonstration scope.",
            "relation": "direct-demonstration"
          }
        ],
        "contextSourceIds": [
          "core-12-1",
          "core-12-2",
          "core-12-3",
          "core-12-4"
        ],
        "editorialProvenance": {
          "status": "substantive-editorial-review",
          "reviewers": [
            "GShips Project editorial synthesis"
          ],
          "conflicts": [
            "Publisher intends to explore a commercial venture based on some GShips work."
          ]
        },
        "whatWouldChange": "A long-duration red-team and succession program that repeatedly recovers clocks, identities, keys, revocation state, archives, commands, and cryptographic migrations without Earth, original experts, or one trusted implementation would raise readiness.",
        "highConsequence": [
          "cybersecurity",
          "governance"
        ]
      }
    },
    {
      "recordType": "claim",
      "recordId": "claim-12-06",
      "title": "Insiders, collusion, governance capture, compromised suppliers, corrupted hardware, malicious maintenance, radiation faults, operator error, and generational loss of expertise must be addressed without turning safety monitoring into surveillance or political control.",
      "publicPath": "/claims/claim-12-06",
      "recordFingerprint": "e661cc2789a8cd078b10a5fa6f5f4bb267c1dcdcc4156a6fd1870fa857a41db2",
      "reviewRequirements": {
        "minimumIndependentApprovals": 2,
        "highConsequenceDomains": [
          "cybersecurity",
          "governance",
          "human-rights",
          "life-support-continuity",
          "privacy"
        ],
        "requiredDomainCodes": [
          "defensive-cyber-safety",
          "governance-law-rights"
        ],
        "requiredComplementaryScopeGroups": [
          {
            "id": "domain-method",
            "scopeClass": "domain-method",
            "oneOf": [
              "defensive-cyber-safety",
              "governance-law-rights",
              "security-assurance"
            ]
          },
          {
            "id": "rights-public-interest",
            "scopeClass": "rights-public-interest",
            "oneOf": [
              "affected-public-rights"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [
        "src-cr-nist-aml-100-2e2025",
        "src-cr-nist-controls-80053r5",
        "src-cr-nist-scrm-800161r1u1",
        "src-im-nist-ot-80082r3"
      ],
      "snapshot": {
        "id": "claim-12-06",
        "systemSlug": "cybersecurity",
        "kind": "unknown",
        "statementRef": {
          "field": "unknowns",
          "index": 1
        },
        "statement": "Insiders, collusion, governance capture, compromised suppliers, corrupted hardware, malicious maintenance, radiation faults, operator error, and generational loss of expertise must be addressed without turning safety monitoring into surveillance or political control.",
        "statementFingerprint": "214d781b1e11d13c5cdd7ff5867c7ed4cdbec323c647bf0dd76fcdab69f548b6",
        "assessment": {
          "status": "editorial-assessed",
          "basis": "normative",
          "readiness": "early-research",
          "confidence": "supported",
          "rationale": "Current OT, supply-chain, security-control, and adversarial-AI guidance supports the inclusion of insiders, suppliers, hardware and software corruption, maintenance access, operator error, and poisoned models. Governance capture, generational expertise loss, and limits on surveillance are essential normative extensions for a closed society; the cited technical sources do not resolve their constitutional implementation."
        },
        "citations": [
          {
            "sourceId": "src-cr-nist-scrm-800161r1u1",
            "locator": "Executive summary and sections 2 and 3 on malicious functionality, counterfeit, tampering, poor development and manufacturing practice, supplier visibility, and multilevel lifecycle risk.",
            "relation": "direct-normative-authority"
          },
          {
            "sourceId": "src-im-nist-ot-80082r3",
            "locator": "Threat and vulnerability sections covering insiders, maintenance, remote access, supply chain, configuration, operator error, availability, safety, and physical consequences.",
            "relation": "direct-normative-authority"
          },
          {
            "sourceId": "src-cr-nist-controls-80053r5",
            "locator": "Personnel Security, Access Control, Audit and Accountability, Privacy, Supply Chain Risk Management, Maintenance, Incident Response, and System Integrity control families.",
            "relation": "direct-normative-authority"
          },
          {
            "sourceId": "src-cr-nist-aml-100-2e2025",
            "locator": "Taxonomy chapters covering predictive- and generative-AI poisoning, evasion, privacy, misuse, lifecycle stages, attacker capabilities, and mitigation limitations.",
            "relation": "direct-normative-authority"
          }
        ],
        "contextSourceIds": [
          "core-12-1",
          "core-12-2",
          "core-12-3",
          "core-12-4"
        ],
        "editorialProvenance": {
          "status": "substantive-editorial-review",
          "reviewers": [
            "GShips Project editorial synthesis"
          ],
          "conflicts": [
            "Publisher intends to explore a commercial venture based on some GShips work; no entity, funding, customer, sponsor, or partner relationship with cited organizations is reported."
          ]
        },
        "whatWouldChange": "Long-duration habitat trials with independent civil-rights review could identify a narrower threat set or controls that provide equivalent safety with less monitoring. Evidence that proposed telemetry, identity, or emergency powers predictably enable coercion or suppress truthful reporting should remove or redesign those controls, even if they improve technical detection.",
        "highConsequence": [
          "cybersecurity",
          "governance",
          "privacy",
          "human-rights",
          "life-support-continuity"
        ]
      }
    },
    {
      "recordType": "claim",
      "recordId": "claim-12-07",
      "title": "Onboard manufacturing makes malicious designs, poisoned toolchains, compromised metrology, counterfeit replacement parts, and configuration drift cyber-physical threats.",
      "publicPath": "/claims/claim-12-07",
      "recordFingerprint": "aa41b5d69f1e2cb946f156453cc5e43165f992ffba714ec0b1562413e4751e5c",
      "reviewRequirements": {
        "minimumIndependentApprovals": 2,
        "highConsequenceDomains": [
          "cybersecurity",
          "spacecraft-safety",
          "supply-chain"
        ],
        "requiredDomainCodes": [
          "defensive-cyber-safety"
        ],
        "requiredComplementaryScopeGroups": [
          {
            "id": "domain-method",
            "scopeClass": "domain-method",
            "oneOf": [
              "defensive-cyber-safety",
              "security-assurance"
            ]
          },
          {
            "id": "rights-public-interest",
            "scopeClass": "rights-public-interest",
            "oneOf": [
              "affected-public-rights"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [
        "src-im-nasa-eee-873910",
        "src-im-nasa-metrology-873912",
        "src-im-nasa-std-6030",
        "src-im-nist-ot-80082r3"
      ],
      "snapshot": {
        "id": "claim-12-07",
        "systemSlug": "cybersecurity",
        "kind": "unknown",
        "statementRef": {
          "field": "unknowns",
          "index": 2
        },
        "statement": "Onboard manufacturing makes malicious designs, poisoned toolchains, compromised metrology, counterfeit replacement parts, and configuration drift cyber-physical threats.",
        "statementFingerprint": "652aecb33bcd4c10a3c944775abc632ed556d9e8ee441a6b895d6cdfe4481ec3",
        "assessment": {
          "status": "editorial-assessed",
          "basis": "modeled",
          "readiness": "early-research",
          "confidence": "supported",
          "rationale": "Manufacturing records, controller software, toolpaths, process limits, metrology corrections, and acceptance criteria directly govern physical outputs. Current OT security and NASA manufacturing assurance controls support the threat pathways, while a generation-scale adversarial factory test has not been performed."
        },
        "citations": [
          {
            "sourceId": "src-im-nist-ot-80082r3",
            "locator": "Sections on manufacturing OT, supply-chain compromise, unauthorized change, maintenance access, segmentation, integrity, and recovery.",
            "relation": "direct-normative-authority"
          },
          {
            "sourceId": "src-im-nasa-std-6030",
            "locator": "Requirements covering authorized process specifications, feedstock, machine qualification, digital build files, configuration control, inspection, and acceptance.",
            "relation": "direct-normative-authority"
          },
          {
            "sourceId": "src-im-nasa-metrology-873912",
            "locator": "Requirements for selection, calibration, control, traceability, and use of measuring and test equipment affecting safety or mission success.",
            "relation": "direct-method"
          },
          {
            "sourceId": "src-im-nasa-eee-873910",
            "locator": "Scope and requirements for electronic-part acquisition, traceability, testing, handling, storage, application, and supply risk.",
            "relation": "direct-normative-authority"
          }
        ],
        "contextSourceIds": [
          "core-12-1",
          "core-12-2",
          "core-12-3",
          "core-12-4"
        ],
        "editorialProvenance": {
          "status": "substantive-editorial-review",
          "reviewers": [
            "GShips Project editorial synthesis"
          ],
          "conflicts": [
            "Publisher intends to explore a commercial venture based on some GShips work."
          ]
        },
        "whatWouldChange": "A representative cyber-physical factory exercise that controls unauthorized designs and process changes, detects poisoned tools and calibration, rejects counterfeit parts, restores a known-good configuration, and measures residual defects would change confidence and required controls.",
        "highConsequence": [
          "cybersecurity",
          "supply-chain",
          "spacecraft-safety"
        ]
      }
    },
    {
      "recordType": "claim",
      "recordId": "claim-12-08",
      "title": "Disconnected trust fabrics, update airlocks, recovery vaults, and cyber ranges benefit critical infrastructure and remote industry.",
      "publicPath": "/claims/claim-12-08",
      "recordFingerprint": "cf9e9af24876befe4386e5d20c5bd3940c82a2f55d410ae762b76cc43357ca22",
      "reviewRequirements": {
        "minimumIndependentApprovals": 2,
        "highConsequenceDomains": [
          "critical-infrastructure",
          "cybersecurity",
          "dual-use"
        ],
        "requiredDomainCodes": [
          "defensive-cyber-safety",
          "dual-use-risk"
        ],
        "requiredComplementaryScopeGroups": [
          {
            "id": "domain-method",
            "scopeClass": "domain-method",
            "oneOf": [
              "defensive-cyber-safety",
              "dual-use-risk",
              "security-assurance"
            ]
          },
          {
            "id": "rights-public-interest",
            "scopeClass": "rights-public-interest",
            "oneOf": [
              "affected-public-rights"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [
        "src-cr-nist-cyber-resilience-800160v2r1",
        "src-cr-nist-firmware-800193",
        "src-cr-nist-incident-80061r3",
        "src-im-nist-ot-80082r3"
      ],
      "snapshot": {
        "id": "claim-12-08",
        "systemSlug": "cybersecurity",
        "kind": "earth benefit",
        "statementRef": {
          "field": "earthBenefits",
          "index": 0
        },
        "statement": "Disconnected trust fabrics, update airlocks, recovery vaults, and cyber ranges benefit critical infrastructure and remote industry.",
        "statementFingerprint": "3091af12d5127935922a8d65792b3d50cbee8d89257ecb9341ecfe8844f77279",
        "assessment": {
          "status": "editorial-assessed",
          "basis": "proposed",
          "readiness": "early-research",
          "confidence": "tentative",
          "rationale": "Disconnected recovery, segmented operation, controlled updates, firmware recovery, and incident exercises are relevant to current critical infrastructure and remote operations. The specific bundle described by the claim has not been evaluated as one intervention, so Earthside benefit is plausible but not established net of cost, complexity, workload, accessibility, and governance risk."
        },
        "citations": [
          {
            "sourceId": "src-cr-nist-cyber-resilience-800160v2r1",
            "locator": "Cyber-resiliency techniques and approaches including segmentation, diversity, redundancy, substantiated integrity, predefined segmentation, and recovery.",
            "relation": "direct-normative-authority"
          },
          {
            "sourceId": "src-cr-nist-firmware-800193",
            "locator": "Protect, detect, and recover model for platform firmware and critical data, including roots of trust.",
            "relation": "context-only"
          },
          {
            "sourceId": "src-cr-nist-incident-80061r3",
            "locator": "CSF 2.0 profile recommendations for preparation, detection, response, recovery, communications, and improvement.",
            "relation": "direct-normative-authority"
          },
          {
            "sourceId": "src-im-nist-ot-80082r3",
            "locator": "OT architectures, segmentation, incident response, recovery, safety, and availability constraints relevant to remote and critical industry.",
            "relation": "context-only"
          }
        ],
        "contextSourceIds": [
          "core-12-1",
          "core-12-2",
          "core-12-3",
          "core-12-4"
        ],
        "editorialProvenance": {
          "status": "substantive-editorial-review",
          "reviewers": [
            "GShips Project editorial synthesis"
          ],
          "conflicts": [
            "Publisher intends to explore a commercial venture based on some GShips work; no entity, funding, customer, sponsor, or partner relationship with cited organizations is reported."
          ]
        },
        "whatWouldChange": "Controlled deployments in remote utilities, hospitals, industrial sites, or isolated research stations should measure safe-service continuity, recovery time, false isolation, operator burden, accessibility, privacy impact, and total cost against a baseline. Consistent harm or no benefit would weaken or reverse the Earth-benefit claim.",
        "highConsequence": [
          "cybersecurity",
          "critical-infrastructure",
          "dual-use"
        ]
      }
    },
    {
      "recordType": "claim",
      "recordId": "claim-12-09",
      "title": "Crypto agility and toolchain escrow reduce obsolescence risk in medical, energy, transport, and public systems.",
      "publicPath": "/claims/claim-12-09",
      "recordFingerprint": "4c3588aab47e1175acc7a32a66fd16e23f01df3fd603f3d4005e2e5503935290",
      "reviewRequirements": {
        "minimumIndependentApprovals": 2,
        "highConsequenceDomains": [
          "critical-infrastructure",
          "cybersecurity",
          "software-supply-chain"
        ],
        "requiredDomainCodes": [
          "defensive-cyber-safety"
        ],
        "requiredComplementaryScopeGroups": [
          {
            "id": "domain-method",
            "scopeClass": "domain-method",
            "oneOf": [
              "defensive-cyber-safety",
              "security-assurance"
            ]
          },
          {
            "id": "rights-public-interest",
            "scopeClass": "rights-public-interest",
            "oneOf": [
              "affected-public-rights"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [
        "src-cr-nist-crypto-agility-cswp39u1",
        "src-cr-nist-key-management-80057p1r5",
        "src-cr-nist-scrm-800161r1u1",
        "src-cr-nist-ssdf-800218"
      ],
      "snapshot": {
        "id": "claim-12-09",
        "systemSlug": "cybersecurity",
        "kind": "earth benefit",
        "statementRef": {
          "field": "earthBenefits",
          "index": 1
        },
        "statement": "Crypto agility and toolchain escrow reduce obsolescence risk in medical, energy, transport, and public systems.",
        "statementFingerprint": "d727ace64c3dbae511612cfdaa6d61d9dd6a06428fee0a02ce3b3c311bcd8d36",
        "assessment": {
          "status": "editorial-assessed",
          "basis": "proposed",
          "readiness": "major-scale-up",
          "confidence": "supported",
          "rationale": "NIST guidance directly treats algorithm replacement, cryptographic inventories, key lifecycle, secure development, supply-chain visibility, and transition continuity as current risk-management needs. Preserving build tools, source, specifications, and recovery knowledge as an escrowed local capability is a systems inference rather than a directly demonstrated cross-sector program."
        },
        "citations": [
          {
            "sourceId": "src-cr-nist-crypto-agility-cswp39u1",
            "locator": "Sections on cryptographic discovery and inventory, strategic planning, protocols, applications, operational mechanisms, transition dependencies, trade-offs, and metrics.",
            "relation": "direct-normative-authority"
          },
          {
            "sourceId": "src-cr-nist-key-management-80057p1r5",
            "locator": "Key-management lifecycle, cryptoperiods, compromise, backup, recovery, archival, and transition-related protection requirements.",
            "relation": "direct-normative-authority"
          },
          {
            "sourceId": "src-cr-nist-ssdf-800218",
            "locator": "Practices PO.1 through PO.5, PS.1 through PS.3, PW.4 through PW.9, and RV.1 through RV.3 for organizational preparation, protected artifacts, secure production, and vulnerability response.",
            "relation": "direct-normative-authority"
          },
          {
            "sourceId": "src-cr-nist-scrm-800161r1u1",
            "locator": "Lifecycle and supplier-risk guidance addressing provenance, reduced visibility, dependencies, maintenance, and product or service continuity.",
            "relation": "context-only"
          }
        ],
        "contextSourceIds": [
          "core-12-1",
          "core-12-2",
          "core-12-3",
          "core-12-4"
        ],
        "editorialProvenance": {
          "status": "substantive-editorial-review",
          "reviewers": [
            "GShips Project editorial synthesis"
          ],
          "conflicts": [
            "Publisher intends to explore a commercial venture based on some GShips work; no entity, funding, customer, sponsor, or partner relationship with cited organizations is reported."
          ]
        },
        "whatWouldChange": "Longitudinal evidence from medical, energy, transport, or public systems should compare migration time, outage, stranded assets, security regressions, and recovery with and without maintained inventories and locally recoverable toolchains. Evidence that escrow increases compromise or obsolescence risk more than it reduces transition risk would narrow the claim.",
        "highConsequence": [
          "cybersecurity",
          "critical-infrastructure",
          "software-supply-chain"
        ]
      }
    },
    {
      "recordType": "claim",
      "recordId": "claim-12-10",
      "title": "Mixed crews must repeatedly isolate a compromised zone, maintain life support, investigate locally, rebuild from known-good material, and rejoin safely.",
      "publicPath": "/claims/claim-12-10",
      "recordFingerprint": "718e87306ab83c20b2c477e928406ce5697e01b1a5b64ab9cde6d6fbcbe148be",
      "reviewRequirements": {
        "minimumIndependentApprovals": 2,
        "highConsequenceDomains": [
          "cybersecurity",
          "dual-use",
          "governance",
          "life-support-continuity",
          "spacecraft-safety"
        ],
        "requiredDomainCodes": [
          "defensive-cyber-safety",
          "dual-use-risk",
          "governance-law-rights"
        ],
        "requiredComplementaryScopeGroups": [
          {
            "id": "domain-method",
            "scopeClass": "domain-method",
            "oneOf": [
              "defensive-cyber-safety",
              "dual-use-risk",
              "governance-law-rights",
              "security-assurance"
            ]
          },
          {
            "id": "rights-public-interest",
            "scopeClass": "rights-public-interest",
            "oneOf": [
              "affected-public-rights"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [
        "src-cr-nist-cyber-resilience-800160v2r1",
        "src-cr-nist-incident-80061r3",
        "src-cr-nist-recovery-800184",
        "src-im-nist-ot-80082r3"
      ],
      "snapshot": {
        "id": "claim-12-10",
        "systemSlug": "cybersecurity",
        "kind": "decision gate",
        "statementRef": {
          "field": "gate"
        },
        "statement": "Mixed crews must repeatedly isolate a compromised zone, maintain life support, investigate locally, rebuild from known-good material, and rejoin safely.",
        "statementFingerprint": "4f05154a910bd1893b5d593a3436968f8a69ec03158413dd31735a0f241feddc",
        "assessment": {
          "status": "editorial-assessed",
          "basis": "normative",
          "readiness": "early-research",
          "confidence": "supported",
          "rationale": "Current incident-response, OT, cyber-resiliency, and recovery guidance supports preparation, isolation, minimum-safe operation, known-good restoration, testing, and measured recovery. Requiring repeated mixed-crew exercises without Earth is a GShips safety gate; no cited source demonstrates that integrated capability in a generation-scale habitat."
        },
        "citations": [
          {
            "sourceId": "src-cr-nist-incident-80061r3",
            "locator": "Respond and Recover profile outcomes and supporting Govern, Identify, Protect, and Detect recommendations for preparation, analysis, mitigation, communication, and improvement.",
            "relation": "direct-normative-authority"
          },
          {
            "sourceId": "src-cr-nist-recovery-800184",
            "locator": "Sections 2 through 4 on recovery planning, playbooks, testing, metrics, restoration, and lessons learned.",
            "relation": "direct-method"
          },
          {
            "sourceId": "src-cr-nist-cyber-resilience-800160v2r1",
            "locator": "Cyber-resiliency goals and techniques for withstanding, recovering, adapting, segmentation, diversity, redundancy, and substantiated integrity.",
            "relation": "direct-method"
          },
          {
            "sourceId": "src-im-nist-ot-80082r3",
            "locator": "Sections on OT safety and availability constraints, incident response, contingency planning, recovery, architectures, and segmentation.",
            "relation": "scope-boundary"
          }
        ],
        "contextSourceIds": [
          "core-12-1",
          "core-12-2",
          "core-12-3",
          "core-12-4"
        ],
        "editorialProvenance": {
          "status": "substantive-editorial-review",
          "reviewers": [
            "GShips Project editorial synthesis"
          ],
          "conflicts": [
            "Publisher intends to explore a commercial venture based on some GShips work; no entity, funding, customer, sponsor, or partner relationship with cited organizations is reported."
          ]
        },
        "whatWouldChange": "An independently reviewed assurance protocol demonstrating equal or stronger coverage could replace this gate. To satisfy it, changing mixed crews must repeatedly maintain declared minimum safe service while isolated, preserve evidence and rights, rebuild from local known-good material, attest with independent physical checks, reconnect in stages, and recover after injected faults without remote support.",
        "highConsequence": [
          "cybersecurity",
          "spacecraft-safety",
          "life-support-continuity",
          "governance",
          "dual-use"
        ]
      }
    },
    {
      "recordType": "claim-source",
      "recordId": "src-cr-ccsds-350-0-g-3",
      "title": "The Application of Security to CCSDS Protocols",
      "publicPath": "https://public.ccsds.org/Pubs/350x0g3.pdf",
      "recordFingerprint": "44f5371a3c01028d94ba87eb2c3367b47b781a3fe2f7de8e0bb5c7486278d8fb",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "information-science"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "src-cr-ccsds-350-0-g-3",
        "title": "The Application of Security to CCSDS Protocols",
        "authors": [
          "Consultative Committee for Space Data Systems"
        ],
        "publisher": "CCSDS",
        "year": 2019,
        "url": "https://public.ccsds.org/Pubs/350x0g3.pdf",
        "kind": "ccsds-informational-green-book",
        "checkedAt": "2026-07-26",
        "version": "CCSDS 350.0-G-3, Issue 3",
        "scopeNote": "Consensus informational report on security concepts, mechanisms, implementation options, and effects on CCSDS services, primarily for space-ground and ground-space links. The report explicitly is not a CCSDS Recommended Standard and excludes detailed security-analysis and risk-assessment methods."
      }
    },
    {
      "recordType": "claim-source",
      "recordId": "src-cr-cisa-sbom",
      "title": "Software Bill of Materials",
      "publicPath": "https://www.cisa.gov/sbom",
      "recordFingerprint": "d551139e9329c0f04e2480582f3dd9123e7d717b8bfedf5cb6141bc087053d16",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "information-science"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "src-cr-cisa-sbom",
        "title": "Software Bill of Materials",
        "authors": [
          "Cybersecurity and Infrastructure Security Agency"
        ],
        "publisher": "CISA",
        "year": 2026,
        "url": "https://www.cisa.gov/sbom",
        "kind": "government-software-transparency-resource",
        "checkedAt": "2026-07-25",
        "scopeNote": "Official SBOM definition, ecosystem roles, use cases, community resources, and minimum-elements guidance; an SBOM is component evidence rather than proof of safety."
      }
    },
    {
      "recordType": "claim-source",
      "recordId": "src-cr-ietf-rfc9019-suit",
      "title": "A Firmware Update Architecture for Internet of Things",
      "publicPath": "https://www.rfc-editor.org/rfc/rfc9019",
      "recordFingerprint": "f89082ee842c244fde0169bd864fb0a0b2e4390d2b8bda120bbe1fcb414b62e7",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "information-science"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "src-cr-ietf-rfc9019-suit",
        "title": "A Firmware Update Architecture for Internet of Things",
        "authors": [
          "Brendan Moran",
          "Hannes Tschofenig",
          "David Brown",
          "Milton Meriac"
        ],
        "publisher": "IETF",
        "year": 2021,
        "url": "https://www.rfc-editor.org/rfc/rfc9019",
        "kind": "ietf-informational-architecture",
        "checkedAt": "2026-07-25",
        "scopeNote": "Informational IETF architecture for authenticated firmware manifests, stakeholder separation, target matching, sequence control, dependencies, interruption tolerance, and recovery."
      }
    },
    {
      "recordType": "claim-source",
      "recordId": "src-cr-nasa-cryptolib-2023",
      "title": "The State of CryptoLib – The Open-Source Satellite Cryptography Library",
      "publicPath": "https://ntrs.nasa.gov/citations/20230015937",
      "recordFingerprint": "841fcaee2944c6aef6a4e4b5275ddaaea99533977c6de713671c428d94b6998c",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "information-science"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "src-cr-nasa-cryptolib-2023",
        "title": "The State of CryptoLib – The Open-Source Satellite Cryptography Library",
        "authors": [
          "D. Cody Cutright",
          "Scott A. Zemerick",
          "Robert J. Brown",
          "John P. Lucas",
          "Justin R. Morris"
        ],
        "publisher": "NASA Technical Reports Server",
        "year": 2023,
        "url": "https://ntrs.nasa.gov/citations/20230015937",
        "kind": "nasa-conference-abstract",
        "checkedAt": "2026-07-26",
        "scopeNote": "Professionally reviewed conference record distributed in 2023; NTRS marks the available record onlyAbstract=true. The abstract describes an actively developed open-source C library that aims to be CCSDS Space Data Link Security compliant and reports selected Telecommand, Telemetry, and Advanced Orbiting Systems encryption and decryption functions. It does not establish CCSDS conformance, secure implementation, operational deployment, flight qualification, key-management assurance, or long-duration maintenance."
      }
    },
    {
      "recordType": "claim-source",
      "recordId": "src-cr-nasa-space-security-bpg-revb",
      "title": "Space Security: Best Practices Guide",
      "publicPath": "https://swehb.nasa.gov/download/attachments/166592616/Space%20Security%20Best%20Practices%20Guide%20BPG%20REV%20B.pdf?api=v2",
      "recordFingerprint": "49def0ff9598b6f4abebd7c72c8abe70acd2cba861d8cb9407389b95a0ef3d94",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "information-science"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "src-cr-nasa-space-security-bpg-revb",
        "title": "Space Security: Best Practices Guide",
        "authors": [
          "National Aeronautics and Space Administration"
        ],
        "publisher": "NASA",
        "year": 2024,
        "url": "https://swehb.nasa.gov/download/attachments/166592616/Space%20Security%20Best%20Practices%20Guide%20BPG%20REV%20B.pdf?api=v2",
        "kind": "nasa-space-security-guidance",
        "checkedAt": "2026-07-26",
        "version": "Revision B",
        "documentDate": "2024-01-19",
        "scopeNote": "Public NASA guidance translating selected NIST SP 800-53 controls into space-vehicle and ground-segment mission language. It is a risk-based starting point and expressly does not replace required plans or establish a certified architecture, flight qualification, or long-duration assurance."
      }
    },
    {
      "recordType": "claim-source",
      "recordId": "src-cr-nasa-std-1006a",
      "title": "Space System Protection Standard",
      "publicPath": "https://standards.nasa.gov/standard/NASA/NASA-STD-1006",
      "recordFingerprint": "21bc08c8476b722c9011a875a0feeef60390048860f419d797f96be3a5cf998a",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "information-science"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "src-cr-nasa-std-1006a",
        "title": "Space System Protection Standard",
        "authors": [
          "National Aeronautics and Space Administration"
        ],
        "publisher": "NASA Technical Standards System",
        "year": 2022,
        "url": "https://standards.nasa.gov/standard/NASA/NASA-STD-1006",
        "kind": "active-nasa-mandatory-standard",
        "checkedAt": "2026-07-26",
        "version": "A",
        "documentDate": "2022-07-15",
        "status": "ACTIVE",
        "reviewDue": "2027-07-15",
        "scopeNote": "Active Agency-level protection requirements intended to make NASA missions resilient to threats. The standard is normative authority for its NASA scope, not demonstration that a particular system satisfies the requirements or that a generation-ship architecture is integrated or assured."
      }
    },
    {
      "recordType": "claim-source",
      "recordId": "src-cr-nist-controls-80053r5",
      "title": "Security and Privacy Controls for Information Systems and Organizations",
      "publicPath": "https://doi.org/10.6028/NIST.SP.800-53r5",
      "recordFingerprint": "efe4dc6860fbdda228dced85b87695df8d60684aeb6526e328be4724db7cc583",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "information-science"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "src-cr-nist-controls-80053r5",
        "title": "Security and Privacy Controls for Information Systems and Organizations",
        "authors": [
          "Joint Task Force"
        ],
        "publisher": "NIST",
        "year": 2020,
        "url": "https://doi.org/10.6028/NIST.SP.800-53r5",
        "kind": "government-security-privacy-control-catalog",
        "checkedAt": "2026-07-25",
        "scopeNote": "Control families spanning access, audit, contingency, identity, incident response, privacy, supply chain, communications, and system integrity; a catalog to tailor, not a certified architecture."
      }
    },
    {
      "recordType": "claim-source",
      "recordId": "src-cr-nist-crypto-agility-cswp39u1",
      "title": "Considerations for Achieving Crypto Agility: Strategies and Practices",
      "publicPath": "https://csrc.nist.gov/pubs/cswp/39/upd1/considerations-for-achieving-crypto-agility/final",
      "recordFingerprint": "e00c46443bd97a74130ad2e19af942cfe9a635c7eea66e135de4171632673b05",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "information-science"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "src-cr-nist-crypto-agility-cswp39u1",
        "title": "Considerations for Achieving Crypto Agility: Strategies and Practices",
        "authors": [
          "Elaine Barker",
          "Lily Chen",
          "David Cooper",
          "Dustin Moody",
          "Andrew Regenscheid",
          "Murugiah Souppaya",
          "William Newhouse",
          "Russ Housley",
          "Sean Turner",
          "William Barker",
          "Karen Kent"
        ],
        "publisher": "NIST",
        "year": 2026,
        "url": "https://csrc.nist.gov/pubs/cswp/39/upd1/considerations-for-achieving-crypto-agility/final",
        "kind": "government-cryptographic-transition-guidance",
        "checkedAt": "2026-07-25",
        "scopeNote": "Inventory, discovery, operational mechanisms, transition strategies, protocol and application considerations, trade-offs, and open work for cryptographic agility; updated through 2026-06-29."
      }
    },
    {
      "recordType": "claim-source",
      "recordId": "src-cr-nist-cyber-resilience-800160v2r1",
      "title": "Developing Cyber-Resilient Systems: A Systems Security Engineering Approach",
      "publicPath": "https://doi.org/10.6028/NIST.SP.800-160v2r1",
      "recordFingerprint": "44c9cb7acf30fe7dae9002044900433af81212da661b965f9264af72a409aec1",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "information-science"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "src-cr-nist-cyber-resilience-800160v2r1",
        "title": "Developing Cyber-Resilient Systems: A Systems Security Engineering Approach",
        "authors": [
          "National Institute of Standards and Technology"
        ],
        "publisher": "NIST",
        "year": 2021,
        "url": "https://doi.org/10.6028/NIST.SP.800-160v2r1",
        "kind": "government-cyber-resilience-guidance",
        "checkedAt": "2026-07-25",
        "scopeNote": "Cyber-resiliency goals, objectives, techniques, approaches, design principles, and systems-engineering lifecycle; not a generation-ship architecture or certification."
      }
    },
    {
      "recordType": "claim-source",
      "recordId": "src-cr-nist-fips203-mlkem",
      "title": "Module-Lattice-Based Key-Encapsulation Mechanism Standard",
      "publicPath": "https://doi.org/10.6028/NIST.FIPS.203",
      "recordFingerprint": "a8bc98ef3f8daf79edc2206df6273a4f8e046a98b172df40a11061d4b936f78a",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "information-science"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "src-cr-nist-fips203-mlkem",
        "title": "Module-Lattice-Based Key-Encapsulation Mechanism Standard",
        "authors": [
          "National Institute of Standards and Technology"
        ],
        "publisher": "NIST",
        "year": 2024,
        "url": "https://doi.org/10.6028/NIST.FIPS.203",
        "kind": "government-cryptographic-standard",
        "checkedAt": "2026-07-25",
        "scopeNote": "ML-KEM algorithms and parameter sets for establishing shared secrets; NIST lists potential updates and does not claim century-scale security or implementation assurance."
      }
    },
    {
      "recordType": "claim-source",
      "recordId": "src-cr-nist-fips204-mldsa",
      "title": "Module-Lattice-Based Digital Signature Standard",
      "publicPath": "https://doi.org/10.6028/NIST.FIPS.204",
      "recordFingerprint": "4b47fc94489002ab20d4e7858bcf1ddfce9f09ec939fa84ced8271cb124eba1e",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "information-science"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "src-cr-nist-fips204-mldsa",
        "title": "Module-Lattice-Based Digital Signature Standard",
        "authors": [
          "National Institute of Standards and Technology"
        ],
        "publisher": "NIST",
        "year": 2024,
        "url": "https://doi.org/10.6028/NIST.FIPS.204",
        "kind": "government-cryptographic-standard",
        "checkedAt": "2026-07-25",
        "scopeNote": "ML-DSA digital-signature algorithms and parameter sets; standardization does not establish indefinite security, implementation correctness, or archival continuity."
      }
    },
    {
      "recordType": "claim-source",
      "recordId": "src-cr-nist-firmware-800193",
      "title": "Platform Firmware Resiliency Guidelines",
      "publicPath": "https://doi.org/10.6028/NIST.SP.800-193",
      "recordFingerprint": "08984a00ed4540ac34b3290412d4c5c6eddd595f4207fee8aa92a63c48b9017c",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "information-science"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "src-cr-nist-firmware-800193",
        "title": "Platform Firmware Resiliency Guidelines",
        "authors": [
          "Andrew Regenscheid"
        ],
        "publisher": "NIST",
        "year": 2018,
        "url": "https://doi.org/10.6028/NIST.SP.800-193",
        "kind": "government-platform-resilience-guidance",
        "checkedAt": "2026-07-25",
        "scopeNote": "Roots of trust and mechanisms to protect, detect, and recover platform firmware and critical data after destructive attacks."
      }
    },
    {
      "recordType": "claim-source",
      "recordId": "src-cr-nist-incident-80061r3",
      "title": "Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile",
      "publicPath": "https://doi.org/10.6028/NIST.SP.800-61r3",
      "recordFingerprint": "5f3dd381a84f21187a92324d4aa5da91ce04e14d59aef5f5faaca6227359d59d",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "information-science"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "src-cr-nist-incident-80061r3",
        "title": "Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile",
        "authors": [
          "Alexander Nelson",
          "Sanjay Rekhi",
          "Murugiah Souppaya",
          "Karen Scarfone"
        ],
        "publisher": "NIST",
        "year": 2025,
        "url": "https://doi.org/10.6028/NIST.SP.800-61r3",
        "kind": "government-incident-response-guidance",
        "checkedAt": "2026-07-25",
        "scopeNote": "Incident preparation, detection, response, recovery, communications, analysis, mitigation, and improvement across CSF 2.0 functions."
      }
    },
    {
      "recordType": "claim-source",
      "recordId": "src-cr-nist-key-management-80057p1r5",
      "title": "Recommendation for Key Management: Part 1 — General",
      "publicPath": "https://doi.org/10.6028/NIST.SP.800-57pt1r5",
      "recordFingerprint": "8de5e1eb786969d11a6a1544085a1663f7c54cfb69eb79f4de3da9231844c3cf",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "information-science"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "src-cr-nist-key-management-80057p1r5",
        "title": "Recommendation for Key Management: Part 1 — General",
        "authors": [
          "Elaine Barker"
        ],
        "publisher": "NIST",
        "year": 2020,
        "url": "https://doi.org/10.6028/NIST.SP.800-57pt1r5",
        "kind": "government-key-management-guidance",
        "checkedAt": "2026-07-25",
        "scopeNote": "Cryptographic services, key types, lifecycle functions, protection, compromise, backup, recovery, archival, and destruction."
      }
    },
    {
      "recordType": "claim-source",
      "recordId": "src-cr-nist-recovery-800184",
      "title": "Guide for Cybersecurity Event Recovery",
      "publicPath": "https://doi.org/10.6028/NIST.SP.800-184",
      "recordFingerprint": "d43cc61a580591a7ef3ddd073f2913df1e480bf7d7866279bca0d53880fd780c",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "information-science"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "src-cr-nist-recovery-800184",
        "title": "Guide for Cybersecurity Event Recovery",
        "authors": [
          "Michael Bartock",
          "Jeffrey Cichonski",
          "Murugiah Souppaya",
          "Matthew Smith",
          "Greg Witte",
          "Karen Scarfone"
        ],
        "publisher": "NIST",
        "year": 2016,
        "url": "https://doi.org/10.6028/NIST.SP.800-184",
        "kind": "government-cyber-recovery-guidance",
        "checkedAt": "2026-07-25",
        "scopeNote": "Recovery planning, playbooks, testing, metrics, restoration, and improvement for current organizations; assumes terrestrial institutional support."
      }
    },
    {
      "recordType": "claim-source",
      "recordId": "src-cr-nist-scrm-800161r1u1",
      "title": "Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations",
      "publicPath": "https://doi.org/10.6028/NIST.SP.800-161r1-upd1",
      "recordFingerprint": "02be470198b0c48432a90e4c5ac8374c588bad818fe7b37a7b663719ccab90bf",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "information-science"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "src-cr-nist-scrm-800161r1u1",
        "title": "Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations",
        "authors": [
          "Jon Boyens",
          "Angela Smith",
          "Nadya Bartol",
          "Kris Winkler",
          "Alex Holbrook",
          "Matthew Fallon"
        ],
        "publisher": "NIST",
        "year": 2024,
        "url": "https://doi.org/10.6028/NIST.SP.800-161r1-upd1",
        "kind": "government-supply-chain-risk-guidance",
        "checkedAt": "2026-07-25",
        "scopeNote": "Multilevel lifecycle guidance for identifying, assessing, and mitigating malicious functionality, counterfeit, tampering, and poor development or manufacturing practice."
      }
    },
    {
      "recordType": "claim-source",
      "recordId": "src-cr-nist-ssdf-800218",
      "title": "Secure Software Development Framework (SSDF) Version 1.1",
      "publicPath": "https://doi.org/10.6028/NIST.SP.800-218",
      "recordFingerprint": "bda553d2c9f6bc9091b819eb153491cf8392cac73836f86a15eefee22fac1003",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "information-science"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "src-cr-nist-ssdf-800218",
        "title": "Secure Software Development Framework (SSDF) Version 1.1",
        "authors": [
          "Murugiah Souppaya",
          "Karen Scarfone",
          "Donna Dodson"
        ],
        "publisher": "NIST",
        "year": 2022,
        "url": "https://doi.org/10.6028/NIST.SP.800-218",
        "kind": "government-secure-development-guidance",
        "checkedAt": "2026-07-25",
        "scopeNote": "Outcome-based practices for preparing an organization, protecting software, producing well-secured releases, and responding to vulnerabilities."
      }
    },
    {
      "recordType": "claim-source",
      "recordId": "src-cr-nist-zero-trust-800207",
      "title": "Zero Trust Architecture",
      "publicPath": "https://doi.org/10.6028/NIST.SP.800-207",
      "recordFingerprint": "4084c1d50c6edb3efc017ff0bfe23d5280297df0258c440ca27973d10702e901",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "information-science"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "src-cr-nist-zero-trust-800207",
        "title": "Zero Trust Architecture",
        "authors": [
          "Scott Rose",
          "Oliver Borchert",
          "Stu Mitchell",
          "Sean Connelly"
        ],
        "publisher": "NIST",
        "year": 2020,
        "url": "https://doi.org/10.6028/NIST.SP.800-207",
        "kind": "government-cybersecurity-architecture-guidance",
        "checkedAt": "2026-07-25",
        "scopeNote": "Resource-focused zero-trust tenets, logical components, deployment models, and threats for enterprise systems; does not establish closed-habitat integration."
      }
    },
    {
      "recordType": "claim-source",
      "recordId": "src-im-nasa-eee-873910",
      "title": "Electrical, Electronic, and Electromechanical Parts Assurance Standard",
      "publicPath": "https://standards.nasa.gov/standard/NASA/NASA-STD-873910",
      "recordFingerprint": "7de974366c68ddd53ce47a7829040b0f7d644de2713f873827f7eacbe97c2287",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "information-science"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "src-im-nasa-eee-873910",
        "title": "Electrical, Electronic, and Electromechanical Parts Assurance Standard",
        "authors": [
          "National Aeronautics and Space Administration"
        ],
        "publisher": "NASA",
        "year": 2017,
        "url": "https://standards.nasa.gov/standard/NASA/NASA-STD-873910",
        "kind": "active-electronic-parts-assurance-standard",
        "checkedAt": "2026-07-25",
        "scopeNote": "Selection, acquisition, traceability, testing, handling, packaging, storage, application, and risk control for spaceflight electronic and electromechanical parts."
      }
    },
    {
      "recordType": "claim-source",
      "recordId": "src-im-nasa-metrology-873912",
      "title": "Metrology and Calibration",
      "publicPath": "https://standards.nasa.gov/standard/NASA/NASA-STD-873912",
      "recordFingerprint": "8fa80c312101f162e43d1a51a136596e2cd0ff81f1b218ff7227df062b3e3540",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "information-science"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "src-im-nasa-metrology-873912",
        "title": "Metrology and Calibration",
        "authors": [
          "National Aeronautics and Space Administration"
        ],
        "publisher": "NASA",
        "year": 2024,
        "url": "https://standards.nasa.gov/standard/NASA/NASA-STD-873912",
        "kind": "active-metrology-calibration-standard",
        "checkedAt": "2026-07-25",
        "scopeNote": "Selection, calibration, control, and use of measuring and test equipment whose results affect safety or mission success."
      }
    },
    {
      "recordType": "claim-source",
      "recordId": "src-im-nasa-std-6030",
      "title": "Additive Manufacturing Requirements for Spaceflight Systems",
      "publicPath": "https://standards.nasa.gov/standard/NASA/NASA-STD-6030",
      "recordFingerprint": "7e6a5d45f27e760d46772f9f030ecd9397047f8274aa4525946c18e6d6b34d90",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "information-science"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "src-im-nasa-std-6030",
        "title": "Additive Manufacturing Requirements for Spaceflight Systems",
        "authors": [
          "National Aeronautics and Space Administration"
        ],
        "publisher": "NASA",
        "year": 2021,
        "url": "https://standards.nasa.gov/standard/NASA/NASA-STD-6030",
        "kind": "active-spaceflight-manufacturing-standard",
        "checkedAt": "2026-07-26",
        "version": "Baseline",
        "changeNumber": 0,
        "documentDate": "2021-04-21",
        "status": "ACTIVE",
        "reviewDue": "2026-04-21",
        "freshnessNote": "NASA still marks the baseline ACTIVE even though the listed five-year review date has passed; GShips therefore treats it as current-with-review-due rather than obsolete.",
        "scopeNote": "Requirements for part classification, feedstock and process control, machine qualification, witness material, inspection, acceptance, configuration, and tailored in-space additive manufacturing. This is normative authority for NASA spaceflight hardware, not a demonstration of printed-part performance, autonomous repair, circular manufacturing, or cyber recovery."
      }
    },
    {
      "recordType": "claim-source",
      "recordId": "src-pn-ietf-bpsec",
      "title": "RFC 9172: Bundle Protocol Security",
      "publicPath": "https://www.rfc-editor.org/rfc/rfc9172.html",
      "recordFingerprint": "266d01cc374ffb39ae67ac92d5819b03617401cdf12935e25b0dea13f4a3a1d4",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "information-science"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "src-pn-ietf-bpsec",
        "title": "RFC 9172: Bundle Protocol Security",
        "authors": [
          "Edward Birrane",
          "Kurt McKeever"
        ],
        "publisher": "Internet Engineering Task Force",
        "year": 2022,
        "url": "https://www.rfc-editor.org/rfc/rfc9172.html",
        "kind": "internet-standard",
        "checkedAt": "2026-07-25",
        "scopeNote": "Bundle integrity and confidentiality blocks, security processing, threat assumptions, key-management exclusions, and interoperability requirements."
      }
    },
    {
      "recordType": "claim-source",
      "recordId": "src-pn-jpl-dsac",
      "title": "Working Overtime: NASA's Deep Space Atomic Clock Completes Mission",
      "publicPath": "https://www.jpl.nasa.gov/news/working-overtime-nasas-deep-space-atomic-clock-completes-mission/",
      "recordFingerprint": "eb44d6f5e829543be29e410f9cc10f9588df681ae8fe28478bfb705f4c47c199",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "information-science"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "src-pn-jpl-dsac",
        "title": "Working Overtime: NASA's Deep Space Atomic Clock Completes Mission",
        "authors": [
          "Jet Propulsion Laboratory"
        ],
        "publisher": "NASA Jet Propulsion Laboratory",
        "year": 2021,
        "url": "https://www.jpl.nasa.gov/news/working-overtime-nasas-deep-space-atomic-clock-completes-mission/",
        "kind": "technology-demonstration-record",
        "checkedAt": "2026-07-25",
        "scopeNote": "Deep Space Atomic Clock mission duration, spaceflight technology-demonstration boundary, and reported timing stability over more than twenty days."
      }
    }
  ],
  "linkedRecords": [],
  "referenceSnapshots": [
    {
      "sourceId": "src-cr-ccsds-350-0-g-3",
      "sourceRecordType": "claim-source",
      "sourceFingerprint": "44f5371a3c01028d94ba87eb2c3367b47b781a3fe2f7de8e0bb5c7486278d8fb",
      "snapshot": {
        "id": "src-cr-ccsds-350-0-g-3",
        "title": "The Application of Security to CCSDS Protocols",
        "authors": [
          "Consultative Committee for Space Data Systems"
        ],
        "publisher": "CCSDS",
        "year": 2019,
        "url": "https://public.ccsds.org/Pubs/350x0g3.pdf",
        "kind": "ccsds-informational-green-book",
        "checkedAt": "2026-07-26",
        "version": "CCSDS 350.0-G-3, Issue 3",
        "scopeNote": "Consensus informational report on security concepts, mechanisms, implementation options, and effects on CCSDS services, primarily for space-ground and ground-space links. The report explicitly is not a CCSDS Recommended Standard and excludes detailed security-analysis and risk-assessment methods."
      }
    },
    {
      "sourceId": "src-cr-cisa-sbom",
      "sourceRecordType": "claim-source",
      "sourceFingerprint": "d551139e9329c0f04e2480582f3dd9123e7d717b8bfedf5cb6141bc087053d16",
      "snapshot": {
        "id": "src-cr-cisa-sbom",
        "title": "Software Bill of Materials",
        "authors": [
          "Cybersecurity and Infrastructure Security Agency"
        ],
        "publisher": "CISA",
        "year": 2026,
        "url": "https://www.cisa.gov/sbom",
        "kind": "government-software-transparency-resource",
        "checkedAt": "2026-07-25",
        "scopeNote": "Official SBOM definition, ecosystem roles, use cases, community resources, and minimum-elements guidance; an SBOM is component evidence rather than proof of safety."
      }
    },
    {
      "sourceId": "src-cr-ietf-rfc9019-suit",
      "sourceRecordType": "claim-source",
      "sourceFingerprint": "f89082ee842c244fde0169bd864fb0a0b2e4390d2b8bda120bbe1fcb414b62e7",
      "snapshot": {
        "id": "src-cr-ietf-rfc9019-suit",
        "title": "A Firmware Update Architecture for Internet of Things",
        "authors": [
          "Brendan Moran",
          "Hannes Tschofenig",
          "David Brown",
          "Milton Meriac"
        ],
        "publisher": "IETF",
        "year": 2021,
        "url": "https://www.rfc-editor.org/rfc/rfc9019",
        "kind": "ietf-informational-architecture",
        "checkedAt": "2026-07-25",
        "scopeNote": "Informational IETF architecture for authenticated firmware manifests, stakeholder separation, target matching, sequence control, dependencies, interruption tolerance, and recovery."
      }
    },
    {
      "sourceId": "src-cr-nasa-cryptolib-2023",
      "sourceRecordType": "claim-source",
      "sourceFingerprint": "841fcaee2944c6aef6a4e4b5275ddaaea99533977c6de713671c428d94b6998c",
      "snapshot": {
        "id": "src-cr-nasa-cryptolib-2023",
        "title": "The State of CryptoLib – The Open-Source Satellite Cryptography Library",
        "authors": [
          "D. Cody Cutright",
          "Scott A. Zemerick",
          "Robert J. Brown",
          "John P. Lucas",
          "Justin R. Morris"
        ],
        "publisher": "NASA Technical Reports Server",
        "year": 2023,
        "url": "https://ntrs.nasa.gov/citations/20230015937",
        "kind": "nasa-conference-abstract",
        "checkedAt": "2026-07-26",
        "scopeNote": "Professionally reviewed conference record distributed in 2023; NTRS marks the available record onlyAbstract=true. The abstract describes an actively developed open-source C library that aims to be CCSDS Space Data Link Security compliant and reports selected Telecommand, Telemetry, and Advanced Orbiting Systems encryption and decryption functions. It does not establish CCSDS conformance, secure implementation, operational deployment, flight qualification, key-management assurance, or long-duration maintenance."
      }
    },
    {
      "sourceId": "src-cr-nasa-space-security-bpg-revb",
      "sourceRecordType": "claim-source",
      "sourceFingerprint": "49def0ff9598b6f4abebd7c72c8abe70acd2cba861d8cb9407389b95a0ef3d94",
      "snapshot": {
        "id": "src-cr-nasa-space-security-bpg-revb",
        "title": "Space Security: Best Practices Guide",
        "authors": [
          "National Aeronautics and Space Administration"
        ],
        "publisher": "NASA",
        "year": 2024,
        "url": "https://swehb.nasa.gov/download/attachments/166592616/Space%20Security%20Best%20Practices%20Guide%20BPG%20REV%20B.pdf?api=v2",
        "kind": "nasa-space-security-guidance",
        "checkedAt": "2026-07-26",
        "version": "Revision B",
        "documentDate": "2024-01-19",
        "scopeNote": "Public NASA guidance translating selected NIST SP 800-53 controls into space-vehicle and ground-segment mission language. It is a risk-based starting point and expressly does not replace required plans or establish a certified architecture, flight qualification, or long-duration assurance."
      }
    },
    {
      "sourceId": "src-cr-nasa-std-1006a",
      "sourceRecordType": "claim-source",
      "sourceFingerprint": "21bc08c8476b722c9011a875a0feeef60390048860f419d797f96be3a5cf998a",
      "snapshot": {
        "id": "src-cr-nasa-std-1006a",
        "title": "Space System Protection Standard",
        "authors": [
          "National Aeronautics and Space Administration"
        ],
        "publisher": "NASA Technical Standards System",
        "year": 2022,
        "url": "https://standards.nasa.gov/standard/NASA/NASA-STD-1006",
        "kind": "active-nasa-mandatory-standard",
        "checkedAt": "2026-07-26",
        "version": "A",
        "documentDate": "2022-07-15",
        "status": "ACTIVE",
        "reviewDue": "2027-07-15",
        "scopeNote": "Active Agency-level protection requirements intended to make NASA missions resilient to threats. The standard is normative authority for its NASA scope, not demonstration that a particular system satisfies the requirements or that a generation-ship architecture is integrated or assured."
      }
    },
    {
      "sourceId": "src-cr-nist-aml-100-2e2025",
      "sourceRecordType": "claim-source",
      "sourceFingerprint": "1573c29a25a7b8302f31f3a676e7e80866b6ff58e0c0718e60a38f52ecbd3e5a",
      "snapshot": {
        "id": "src-cr-nist-aml-100-2e2025",
        "title": "Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations",
        "authors": [
          "Apostol Vassilev",
          "Alina Oprea",
          "Alie Fordyce",
          "Hyrum Anderson",
          "Xander Davies",
          "Maia Hamin"
        ],
        "publisher": "NIST",
        "year": 2025,
        "url": "https://doi.org/10.6028/NIST.AI.100-2e2025",
        "kind": "government-ai-security-taxonomy",
        "checkedAt": "2026-07-25",
        "scopeNote": "Predictive- and generative-AI evasion, poisoning, privacy, and misuse taxonomy, lifecycle stages, attacker capabilities, mitigations, and limitations."
      }
    },
    {
      "sourceId": "src-cr-nist-controls-80053r5",
      "sourceRecordType": "claim-source",
      "sourceFingerprint": "efe4dc6860fbdda228dced85b87695df8d60684aeb6526e328be4724db7cc583",
      "snapshot": {
        "id": "src-cr-nist-controls-80053r5",
        "title": "Security and Privacy Controls for Information Systems and Organizations",
        "authors": [
          "Joint Task Force"
        ],
        "publisher": "NIST",
        "year": 2020,
        "url": "https://doi.org/10.6028/NIST.SP.800-53r5",
        "kind": "government-security-privacy-control-catalog",
        "checkedAt": "2026-07-25",
        "scopeNote": "Control families spanning access, audit, contingency, identity, incident response, privacy, supply chain, communications, and system integrity; a catalog to tailor, not a certified architecture."
      }
    },
    {
      "sourceId": "src-cr-nist-crypto-agility-cswp39u1",
      "sourceRecordType": "claim-source",
      "sourceFingerprint": "e00c46443bd97a74130ad2e19af942cfe9a635c7eea66e135de4171632673b05",
      "snapshot": {
        "id": "src-cr-nist-crypto-agility-cswp39u1",
        "title": "Considerations for Achieving Crypto Agility: Strategies and Practices",
        "authors": [
          "Elaine Barker",
          "Lily Chen",
          "David Cooper",
          "Dustin Moody",
          "Andrew Regenscheid",
          "Murugiah Souppaya",
          "William Newhouse",
          "Russ Housley",
          "Sean Turner",
          "William Barker",
          "Karen Kent"
        ],
        "publisher": "NIST",
        "year": 2026,
        "url": "https://csrc.nist.gov/pubs/cswp/39/upd1/considerations-for-achieving-crypto-agility/final",
        "kind": "government-cryptographic-transition-guidance",
        "checkedAt": "2026-07-25",
        "scopeNote": "Inventory, discovery, operational mechanisms, transition strategies, protocol and application considerations, trade-offs, and open work for cryptographic agility; updated through 2026-06-29."
      }
    },
    {
      "sourceId": "src-cr-nist-cyber-resilience-800160v2r1",
      "sourceRecordType": "claim-source",
      "sourceFingerprint": "44c9cb7acf30fe7dae9002044900433af81212da661b965f9264af72a409aec1",
      "snapshot": {
        "id": "src-cr-nist-cyber-resilience-800160v2r1",
        "title": "Developing Cyber-Resilient Systems: A Systems Security Engineering Approach",
        "authors": [
          "National Institute of Standards and Technology"
        ],
        "publisher": "NIST",
        "year": 2021,
        "url": "https://doi.org/10.6028/NIST.SP.800-160v2r1",
        "kind": "government-cyber-resilience-guidance",
        "checkedAt": "2026-07-25",
        "scopeNote": "Cyber-resiliency goals, objectives, techniques, approaches, design principles, and systems-engineering lifecycle; not a generation-ship architecture or certification."
      }
    },
    {
      "sourceId": "src-cr-nist-fips203-mlkem",
      "sourceRecordType": "claim-source",
      "sourceFingerprint": "a8bc98ef3f8daf79edc2206df6273a4f8e046a98b172df40a11061d4b936f78a",
      "snapshot": {
        "id": "src-cr-nist-fips203-mlkem",
        "title": "Module-Lattice-Based Key-Encapsulation Mechanism Standard",
        "authors": [
          "National Institute of Standards and Technology"
        ],
        "publisher": "NIST",
        "year": 2024,
        "url": "https://doi.org/10.6028/NIST.FIPS.203",
        "kind": "government-cryptographic-standard",
        "checkedAt": "2026-07-25",
        "scopeNote": "ML-KEM algorithms and parameter sets for establishing shared secrets; NIST lists potential updates and does not claim century-scale security or implementation assurance."
      }
    },
    {
      "sourceId": "src-cr-nist-fips204-mldsa",
      "sourceRecordType": "claim-source",
      "sourceFingerprint": "4b47fc94489002ab20d4e7858bcf1ddfce9f09ec939fa84ced8271cb124eba1e",
      "snapshot": {
        "id": "src-cr-nist-fips204-mldsa",
        "title": "Module-Lattice-Based Digital Signature Standard",
        "authors": [
          "National Institute of Standards and Technology"
        ],
        "publisher": "NIST",
        "year": 2024,
        "url": "https://doi.org/10.6028/NIST.FIPS.204",
        "kind": "government-cryptographic-standard",
        "checkedAt": "2026-07-25",
        "scopeNote": "ML-DSA digital-signature algorithms and parameter sets; standardization does not establish indefinite security, implementation correctness, or archival continuity."
      }
    },
    {
      "sourceId": "src-cr-nist-firmware-800193",
      "sourceRecordType": "claim-source",
      "sourceFingerprint": "08984a00ed4540ac34b3290412d4c5c6eddd595f4207fee8aa92a63c48b9017c",
      "snapshot": {
        "id": "src-cr-nist-firmware-800193",
        "title": "Platform Firmware Resiliency Guidelines",
        "authors": [
          "Andrew Regenscheid"
        ],
        "publisher": "NIST",
        "year": 2018,
        "url": "https://doi.org/10.6028/NIST.SP.800-193",
        "kind": "government-platform-resilience-guidance",
        "checkedAt": "2026-07-25",
        "scopeNote": "Roots of trust and mechanisms to protect, detect, and recover platform firmware and critical data after destructive attacks."
      }
    },
    {
      "sourceId": "src-cr-nist-incident-80061r3",
      "sourceRecordType": "claim-source",
      "sourceFingerprint": "5f3dd381a84f21187a92324d4aa5da91ce04e14d59aef5f5faaca6227359d59d",
      "snapshot": {
        "id": "src-cr-nist-incident-80061r3",
        "title": "Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile",
        "authors": [
          "Alexander Nelson",
          "Sanjay Rekhi",
          "Murugiah Souppaya",
          "Karen Scarfone"
        ],
        "publisher": "NIST",
        "year": 2025,
        "url": "https://doi.org/10.6028/NIST.SP.800-61r3",
        "kind": "government-incident-response-guidance",
        "checkedAt": "2026-07-25",
        "scopeNote": "Incident preparation, detection, response, recovery, communications, analysis, mitigation, and improvement across CSF 2.0 functions."
      }
    },
    {
      "sourceId": "src-cr-nist-key-management-80057p1r5",
      "sourceRecordType": "claim-source",
      "sourceFingerprint": "8de5e1eb786969d11a6a1544085a1663f7c54cfb69eb79f4de3da9231844c3cf",
      "snapshot": {
        "id": "src-cr-nist-key-management-80057p1r5",
        "title": "Recommendation for Key Management: Part 1 — General",
        "authors": [
          "Elaine Barker"
        ],
        "publisher": "NIST",
        "year": 2020,
        "url": "https://doi.org/10.6028/NIST.SP.800-57pt1r5",
        "kind": "government-key-management-guidance",
        "checkedAt": "2026-07-25",
        "scopeNote": "Cryptographic services, key types, lifecycle functions, protection, compromise, backup, recovery, archival, and destruction."
      }
    },
    {
      "sourceId": "src-cr-nist-recovery-800184",
      "sourceRecordType": "claim-source",
      "sourceFingerprint": "d43cc61a580591a7ef3ddd073f2913df1e480bf7d7866279bca0d53880fd780c",
      "snapshot": {
        "id": "src-cr-nist-recovery-800184",
        "title": "Guide for Cybersecurity Event Recovery",
        "authors": [
          "Michael Bartock",
          "Jeffrey Cichonski",
          "Murugiah Souppaya",
          "Matthew Smith",
          "Greg Witte",
          "Karen Scarfone"
        ],
        "publisher": "NIST",
        "year": 2016,
        "url": "https://doi.org/10.6028/NIST.SP.800-184",
        "kind": "government-cyber-recovery-guidance",
        "checkedAt": "2026-07-25",
        "scopeNote": "Recovery planning, playbooks, testing, metrics, restoration, and improvement for current organizations; assumes terrestrial institutional support."
      }
    },
    {
      "sourceId": "src-cr-nist-scrm-800161r1u1",
      "sourceRecordType": "claim-source",
      "sourceFingerprint": "02be470198b0c48432a90e4c5ac8374c588bad818fe7b37a7b663719ccab90bf",
      "snapshot": {
        "id": "src-cr-nist-scrm-800161r1u1",
        "title": "Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations",
        "authors": [
          "Jon Boyens",
          "Angela Smith",
          "Nadya Bartol",
          "Kris Winkler",
          "Alex Holbrook",
          "Matthew Fallon"
        ],
        "publisher": "NIST",
        "year": 2024,
        "url": "https://doi.org/10.6028/NIST.SP.800-161r1-upd1",
        "kind": "government-supply-chain-risk-guidance",
        "checkedAt": "2026-07-25",
        "scopeNote": "Multilevel lifecycle guidance for identifying, assessing, and mitigating malicious functionality, counterfeit, tampering, and poor development or manufacturing practice."
      }
    },
    {
      "sourceId": "src-cr-nist-ssdf-800218",
      "sourceRecordType": "claim-source",
      "sourceFingerprint": "bda553d2c9f6bc9091b819eb153491cf8392cac73836f86a15eefee22fac1003",
      "snapshot": {
        "id": "src-cr-nist-ssdf-800218",
        "title": "Secure Software Development Framework (SSDF) Version 1.1",
        "authors": [
          "Murugiah Souppaya",
          "Karen Scarfone",
          "Donna Dodson"
        ],
        "publisher": "NIST",
        "year": 2022,
        "url": "https://doi.org/10.6028/NIST.SP.800-218",
        "kind": "government-secure-development-guidance",
        "checkedAt": "2026-07-25",
        "scopeNote": "Outcome-based practices for preparing an organization, protecting software, producing well-secured releases, and responding to vulnerabilities."
      }
    },
    {
      "sourceId": "src-cr-nist-zero-trust-800207",
      "sourceRecordType": "claim-source",
      "sourceFingerprint": "4084c1d50c6edb3efc017ff0bfe23d5280297df0258c440ca27973d10702e901",
      "snapshot": {
        "id": "src-cr-nist-zero-trust-800207",
        "title": "Zero Trust Architecture",
        "authors": [
          "Scott Rose",
          "Oliver Borchert",
          "Stu Mitchell",
          "Sean Connelly"
        ],
        "publisher": "NIST",
        "year": 2020,
        "url": "https://doi.org/10.6028/NIST.SP.800-207",
        "kind": "government-cybersecurity-architecture-guidance",
        "checkedAt": "2026-07-25",
        "scopeNote": "Resource-focused zero-trust tenets, logical components, deployment models, and threats for enterprise systems; does not establish closed-habitat integration."
      }
    },
    {
      "sourceId": "src-im-nasa-eee-873910",
      "sourceRecordType": "claim-source",
      "sourceFingerprint": "7de974366c68ddd53ce47a7829040b0f7d644de2713f873827f7eacbe97c2287",
      "snapshot": {
        "id": "src-im-nasa-eee-873910",
        "title": "Electrical, Electronic, and Electromechanical Parts Assurance Standard",
        "authors": [
          "National Aeronautics and Space Administration"
        ],
        "publisher": "NASA",
        "year": 2017,
        "url": "https://standards.nasa.gov/standard/NASA/NASA-STD-873910",
        "kind": "active-electronic-parts-assurance-standard",
        "checkedAt": "2026-07-25",
        "scopeNote": "Selection, acquisition, traceability, testing, handling, packaging, storage, application, and risk control for spaceflight electronic and electromechanical parts."
      }
    },
    {
      "sourceId": "src-im-nasa-metrology-873912",
      "sourceRecordType": "claim-source",
      "sourceFingerprint": "8fa80c312101f162e43d1a51a136596e2cd0ff81f1b218ff7227df062b3e3540",
      "snapshot": {
        "id": "src-im-nasa-metrology-873912",
        "title": "Metrology and Calibration",
        "authors": [
          "National Aeronautics and Space Administration"
        ],
        "publisher": "NASA",
        "year": 2024,
        "url": "https://standards.nasa.gov/standard/NASA/NASA-STD-873912",
        "kind": "active-metrology-calibration-standard",
        "checkedAt": "2026-07-25",
        "scopeNote": "Selection, calibration, control, and use of measuring and test equipment whose results affect safety or mission success."
      }
    },
    {
      "sourceId": "src-im-nasa-std-6030",
      "sourceRecordType": "claim-source",
      "sourceFingerprint": "7e6a5d45f27e760d46772f9f030ecd9397047f8274aa4525946c18e6d6b34d90",
      "snapshot": {
        "id": "src-im-nasa-std-6030",
        "title": "Additive Manufacturing Requirements for Spaceflight Systems",
        "authors": [
          "National Aeronautics and Space Administration"
        ],
        "publisher": "NASA",
        "year": 2021,
        "url": "https://standards.nasa.gov/standard/NASA/NASA-STD-6030",
        "kind": "active-spaceflight-manufacturing-standard",
        "checkedAt": "2026-07-26",
        "version": "Baseline",
        "changeNumber": 0,
        "documentDate": "2021-04-21",
        "status": "ACTIVE",
        "reviewDue": "2026-04-21",
        "freshnessNote": "NASA still marks the baseline ACTIVE even though the listed five-year review date has passed; GShips therefore treats it as current-with-review-due rather than obsolete.",
        "scopeNote": "Requirements for part classification, feedstock and process control, machine qualification, witness material, inspection, acceptance, configuration, and tailored in-space additive manufacturing. This is normative authority for NASA spaceflight hardware, not a demonstration of printed-part performance, autonomous repair, circular manufacturing, or cyber recovery."
      }
    },
    {
      "sourceId": "src-im-nist-ot-80082r3",
      "sourceRecordType": "claim-source",
      "sourceFingerprint": "079024b69f4ab4aeaa8755b5bf62674b9f4cae4428d4ea97744c9cb78cdb593e",
      "snapshot": {
        "id": "src-im-nist-ot-80082r3",
        "title": "Guide to Operational Technology Security",
        "authors": [
          "Keith Stouffer",
          "Michael Pease",
          "CheeYee Tang",
          "Timothy Zimmerman",
          "Victoria Pillitteri",
          "Suzanne Lightman",
          "Adam Hahn",
          "Stephanie Saravia",
          "Aslam Sherule",
          "Michael Thompson"
        ],
        "publisher": "NIST",
        "year": 2023,
        "url": "https://doi.org/10.6028/NIST.SP.800-82r3",
        "kind": "government-cybersecurity-guidance",
        "checkedAt": "2026-07-25",
        "scopeNote": "Operational-technology architectures, safety and availability constraints, threats, segmentation, supply-chain and maintenance risks, countermeasures, and recovery."
      }
    },
    {
      "sourceId": "src-pn-ccsds-oais",
      "sourceRecordType": "claim-source",
      "sourceFingerprint": "d130fb645b4838a8e446a7a861ad942052dcb493afd6bd7c431bd9e863999212",
      "snapshot": {
        "id": "src-pn-ccsds-oais",
        "title": "Reference Model for an Open Archival Information System",
        "authors": [
          "Consultative Committee for Space Data Systems"
        ],
        "publisher": "CCSDS",
        "year": 2024,
        "url": "https://ccsds.org/searchpubs/entry/3054/",
        "kind": "space-data-systems-standard",
        "checkedAt": "2026-07-25",
        "scopeNote": "OAIS information packages, representation information, designated communities, preservation planning, access, and archive-management functions."
      }
    },
    {
      "sourceId": "src-pn-ietf-bpsec",
      "sourceRecordType": "claim-source",
      "sourceFingerprint": "266d01cc374ffb39ae67ac92d5819b03617401cdf12935e25b0dea13f4a3a1d4",
      "snapshot": {
        "id": "src-pn-ietf-bpsec",
        "title": "RFC 9172: Bundle Protocol Security",
        "authors": [
          "Edward Birrane",
          "Kurt McKeever"
        ],
        "publisher": "Internet Engineering Task Force",
        "year": 2022,
        "url": "https://www.rfc-editor.org/rfc/rfc9172.html",
        "kind": "internet-standard",
        "checkedAt": "2026-07-25",
        "scopeNote": "Bundle integrity and confidentiality blocks, security processing, threat assumptions, key-management exclusions, and interoperability requirements."
      }
    },
    {
      "sourceId": "src-pn-jpl-dsac",
      "sourceRecordType": "claim-source",
      "sourceFingerprint": "eb44d6f5e829543be29e410f9cc10f9588df681ae8fe28478bfb705f4c47c199",
      "snapshot": {
        "id": "src-pn-jpl-dsac",
        "title": "Working Overtime: NASA's Deep Space Atomic Clock Completes Mission",
        "authors": [
          "Jet Propulsion Laboratory"
        ],
        "publisher": "NASA Jet Propulsion Laboratory",
        "year": 2021,
        "url": "https://www.jpl.nasa.gov/news/working-overtime-nasas-deep-space-atomic-clock-completes-mission/",
        "kind": "technology-demonstration-record",
        "checkedAt": "2026-07-25",
        "scopeNote": "Deep Space Atomic Clock mission duration, spaceflight technology-demonstration boundary, and reported timing stability over more than twenty days."
      }
    },
    {
      "sourceId": "official-claim-source-src-cr-ccsds-350-0-g-3",
      "sourceRecordType": "reference-source",
      "sourceFingerprint": "a86142f5fce60a71a0905f1944ad99c11fe7ff14098e81b6e06b38ce2b062243",
      "snapshot": {
        "title": "The Application of Security to CCSDS Protocols",
        "url": "https://public.ccsds.org/Pubs/350x0g3.pdf",
        "checkedAt": null,
        "scopeNote": "Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion.",
        "subjectRecordType": "claim-source",
        "subjectRecordId": "src-cr-ccsds-350-0-g-3"
      }
    },
    {
      "sourceId": "official-claim-source-src-cr-cisa-sbom",
      "sourceRecordType": "reference-source",
      "sourceFingerprint": "8ad5bd5d18cf9ba0ed05394d071fc0d59a42185d10b71351f3e02915cfd71353",
      "snapshot": {
        "title": "Software Bill of Materials",
        "url": "https://www.cisa.gov/sbom",
        "checkedAt": null,
        "scopeNote": "Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion.",
        "subjectRecordType": "claim-source",
        "subjectRecordId": "src-cr-cisa-sbom"
      }
    },
    {
      "sourceId": "official-claim-source-src-cr-ietf-rfc9019-suit",
      "sourceRecordType": "reference-source",
      "sourceFingerprint": "5004da9fb26005706036c9045418cb25c8751ef109f7f10e4e5a1e5eff6b6e7c",
      "snapshot": {
        "title": "A Firmware Update Architecture for Internet of Things",
        "url": "https://www.rfc-editor.org/rfc/rfc9019",
        "checkedAt": null,
        "scopeNote": "Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion.",
        "subjectRecordType": "claim-source",
        "subjectRecordId": "src-cr-ietf-rfc9019-suit"
      }
    },
    {
      "sourceId": "official-claim-source-src-cr-nasa-cryptolib-2023",
      "sourceRecordType": "reference-source",
      "sourceFingerprint": "40ad412fbfaa0c648ca88b0987a6ccae59ddde9351182e318cdeceba790a60c1",
      "snapshot": {
        "title": "The State of CryptoLib – The Open-Source Satellite Cryptography Library",
        "url": "https://ntrs.nasa.gov/citations/20230015937",
        "checkedAt": null,
        "scopeNote": "Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion.",
        "subjectRecordType": "claim-source",
        "subjectRecordId": "src-cr-nasa-cryptolib-2023"
      }
    },
    {
      "sourceId": "official-claim-source-src-cr-nasa-space-security-bpg-revb",
      "sourceRecordType": "reference-source",
      "sourceFingerprint": "f7c2741801ba160965ab6da62bbe88bdd2339c60415087810b8b092704e93807",
      "snapshot": {
        "title": "Space Security: Best Practices Guide",
        "url": "https://swehb.nasa.gov/download/attachments/166592616/Space%20Security%20Best%20Practices%20Guide%20BPG%20REV%20B.pdf?api=v2",
        "checkedAt": null,
        "scopeNote": "Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion.",
        "subjectRecordType": "claim-source",
        "subjectRecordId": "src-cr-nasa-space-security-bpg-revb"
      }
    },
    {
      "sourceId": "official-claim-source-src-cr-nasa-std-1006a",
      "sourceRecordType": "reference-source",
      "sourceFingerprint": "b48c8e7e91dc3ed0a8fa8c23659173cb3b693ebc76d411162fc308ff83d5aafb",
      "snapshot": {
        "title": "Space System Protection Standard",
        "url": "https://standards.nasa.gov/standard/NASA/NASA-STD-1006",
        "checkedAt": null,
        "scopeNote": "Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion.",
        "subjectRecordType": "claim-source",
        "subjectRecordId": "src-cr-nasa-std-1006a"
      }
    },
    {
      "sourceId": "official-claim-source-src-cr-nist-controls-80053r5",
      "sourceRecordType": "reference-source",
      "sourceFingerprint": "9a3ada8c5c146d905b29cc1e413e2fa905c3836da2b7836d128db5b39125dba4",
      "snapshot": {
        "title": "Security and Privacy Controls for Information Systems and Organizations",
        "url": "https://doi.org/10.6028/NIST.SP.800-53r5",
        "checkedAt": null,
        "scopeNote": "Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion.",
        "subjectRecordType": "claim-source",
        "subjectRecordId": "src-cr-nist-controls-80053r5"
      }
    },
    {
      "sourceId": "official-claim-source-src-cr-nist-crypto-agility-cswp39u1",
      "sourceRecordType": "reference-source",
      "sourceFingerprint": "a63db25c84019efdd97e74dad0b0a1905cf61e8e74de79c6d7366073f7a544b2",
      "snapshot": {
        "title": "Considerations for Achieving Crypto Agility: Strategies and Practices",
        "url": "https://csrc.nist.gov/pubs/cswp/39/upd1/considerations-for-achieving-crypto-agility/final",
        "checkedAt": null,
        "scopeNote": "Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion.",
        "subjectRecordType": "claim-source",
        "subjectRecordId": "src-cr-nist-crypto-agility-cswp39u1"
      }
    },
    {
      "sourceId": "official-claim-source-src-cr-nist-cyber-resilience-800160v2r1",
      "sourceRecordType": "reference-source",
      "sourceFingerprint": "8b735effbc75fac1763663ee0d90bf9aea61257c4bcc079db6b07b8f41015a75",
      "snapshot": {
        "title": "Developing Cyber-Resilient Systems: A Systems Security Engineering Approach",
        "url": "https://doi.org/10.6028/NIST.SP.800-160v2r1",
        "checkedAt": null,
        "scopeNote": "Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion.",
        "subjectRecordType": "claim-source",
        "subjectRecordId": "src-cr-nist-cyber-resilience-800160v2r1"
      }
    },
    {
      "sourceId": "official-claim-source-src-cr-nist-fips203-mlkem",
      "sourceRecordType": "reference-source",
      "sourceFingerprint": "d0c7e3c4b6eedbde48c92d0a27014c40ae500772630d2854545744daaeb3c98e",
      "snapshot": {
        "title": "Module-Lattice-Based Key-Encapsulation Mechanism Standard",
        "url": "https://doi.org/10.6028/NIST.FIPS.203",
        "checkedAt": null,
        "scopeNote": "Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion.",
        "subjectRecordType": "claim-source",
        "subjectRecordId": "src-cr-nist-fips203-mlkem"
      }
    },
    {
      "sourceId": "official-claim-source-src-cr-nist-fips204-mldsa",
      "sourceRecordType": "reference-source",
      "sourceFingerprint": "b9f67336a615ca438bf41855ce881364e2746e878f3571765643a2b058e7b879",
      "snapshot": {
        "title": "Module-Lattice-Based Digital Signature Standard",
        "url": "https://doi.org/10.6028/NIST.FIPS.204",
        "checkedAt": null,
        "scopeNote": "Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion.",
        "subjectRecordType": "claim-source",
        "subjectRecordId": "src-cr-nist-fips204-mldsa"
      }
    },
    {
      "sourceId": "official-claim-source-src-cr-nist-firmware-800193",
      "sourceRecordType": "reference-source",
      "sourceFingerprint": "bef51fdba213dfb34855dc5bbaa9801705c0137feaca9eeaf3e21f6fdefa2407",
      "snapshot": {
        "title": "Platform Firmware Resiliency Guidelines",
        "url": "https://doi.org/10.6028/NIST.SP.800-193",
        "checkedAt": null,
        "scopeNote": "Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion.",
        "subjectRecordType": "claim-source",
        "subjectRecordId": "src-cr-nist-firmware-800193"
      }
    },
    {
      "sourceId": "official-claim-source-src-cr-nist-incident-80061r3",
      "sourceRecordType": "reference-source",
      "sourceFingerprint": "b86d4235338d36cf38a3593ae6768af5dc6070c731fcdf52be345c707923829c",
      "snapshot": {
        "title": "Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile",
        "url": "https://doi.org/10.6028/NIST.SP.800-61r3",
        "checkedAt": null,
        "scopeNote": "Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion.",
        "subjectRecordType": "claim-source",
        "subjectRecordId": "src-cr-nist-incident-80061r3"
      }
    },
    {
      "sourceId": "official-claim-source-src-cr-nist-key-management-80057p1r5",
      "sourceRecordType": "reference-source",
      "sourceFingerprint": "cff634fac3513561b69efe8d1c870f1818939af42248106bec73129462052dc6",
      "snapshot": {
        "title": "Recommendation for Key Management: Part 1 — General",
        "url": "https://doi.org/10.6028/NIST.SP.800-57pt1r5",
        "checkedAt": null,
        "scopeNote": "Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion.",
        "subjectRecordType": "claim-source",
        "subjectRecordId": "src-cr-nist-key-management-80057p1r5"
      }
    },
    {
      "sourceId": "official-claim-source-src-cr-nist-recovery-800184",
      "sourceRecordType": "reference-source",
      "sourceFingerprint": "45adc85e81855a49a86b1700fdd41a8794ce28c0fbf5fdc186edba75ca2dc013",
      "snapshot": {
        "title": "Guide for Cybersecurity Event Recovery",
        "url": "https://doi.org/10.6028/NIST.SP.800-184",
        "checkedAt": null,
        "scopeNote": "Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion.",
        "subjectRecordType": "claim-source",
        "subjectRecordId": "src-cr-nist-recovery-800184"
      }
    },
    {
      "sourceId": "official-claim-source-src-cr-nist-scrm-800161r1u1",
      "sourceRecordType": "reference-source",
      "sourceFingerprint": "bc70656502f08d82397647a85e0e0a658e799b28722fca1fdba11120cf4b33df",
      "snapshot": {
        "title": "Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations",
        "url": "https://doi.org/10.6028/NIST.SP.800-161r1-upd1",
        "checkedAt": null,
        "scopeNote": "Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion.",
        "subjectRecordType": "claim-source",
        "subjectRecordId": "src-cr-nist-scrm-800161r1u1"
      }
    },
    {
      "sourceId": "official-claim-source-src-cr-nist-ssdf-800218",
      "sourceRecordType": "reference-source",
      "sourceFingerprint": "5cd722de28cc7500880aa153ae557902fae2b3fa095a2f83ab137b1cd6d85351",
      "snapshot": {
        "title": "Secure Software Development Framework (SSDF) Version 1.1",
        "url": "https://doi.org/10.6028/NIST.SP.800-218",
        "checkedAt": null,
        "scopeNote": "Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion.",
        "subjectRecordType": "claim-source",
        "subjectRecordId": "src-cr-nist-ssdf-800218"
      }
    },
    {
      "sourceId": "official-claim-source-src-cr-nist-zero-trust-800207",
      "sourceRecordType": "reference-source",
      "sourceFingerprint": "d6b902fc8f0575a2a7be4bdabb8767b991221c60e2784b36d83a2e44874f240f",
      "snapshot": {
        "title": "Zero Trust Architecture",
        "url": "https://doi.org/10.6028/NIST.SP.800-207",
        "checkedAt": null,
        "scopeNote": "Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion.",
        "subjectRecordType": "claim-source",
        "subjectRecordId": "src-cr-nist-zero-trust-800207"
      }
    },
    {
      "sourceId": "official-claim-source-src-im-nasa-eee-873910",
      "sourceRecordType": "reference-source",
      "sourceFingerprint": "0cd9a24fa7e15e7cc62119e838b11483a4ab2a218f99543a8a20d460f9c60ffa",
      "snapshot": {
        "title": "Electrical, Electronic, and Electromechanical Parts Assurance Standard",
        "url": "https://standards.nasa.gov/standard/NASA/NASA-STD-873910",
        "checkedAt": null,
        "scopeNote": "Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion.",
        "subjectRecordType": "claim-source",
        "subjectRecordId": "src-im-nasa-eee-873910"
      }
    },
    {
      "sourceId": "official-claim-source-src-im-nasa-metrology-873912",
      "sourceRecordType": "reference-source",
      "sourceFingerprint": "a3b50382dd9f41e9f105d2d0d3867d5afeafcdb8a68b80d98c0975872692fc48",
      "snapshot": {
        "title": "Metrology and Calibration",
        "url": "https://standards.nasa.gov/standard/NASA/NASA-STD-873912",
        "checkedAt": null,
        "scopeNote": "Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion.",
        "subjectRecordType": "claim-source",
        "subjectRecordId": "src-im-nasa-metrology-873912"
      }
    },
    {
      "sourceId": "official-claim-source-src-im-nasa-std-6030",
      "sourceRecordType": "reference-source",
      "sourceFingerprint": "679a41ecc1d685fa0339014c60828d3a73add65d26f63eebd30e8260fe67db94",
      "snapshot": {
        "title": "Additive Manufacturing Requirements for Spaceflight Systems",
        "url": "https://standards.nasa.gov/standard/NASA/NASA-STD-6030",
        "checkedAt": null,
        "scopeNote": "Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion.",
        "subjectRecordType": "claim-source",
        "subjectRecordId": "src-im-nasa-std-6030"
      }
    },
    {
      "sourceId": "official-claim-source-src-pn-ietf-bpsec",
      "sourceRecordType": "reference-source",
      "sourceFingerprint": "8ce6689f23672e15b4cb826b9846e914b0787b371328b8ff02fa68600ece1ab9",
      "snapshot": {
        "title": "RFC 9172: Bundle Protocol Security",
        "url": "https://www.rfc-editor.org/rfc/rfc9172.html",
        "checkedAt": null,
        "scopeNote": "Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion.",
        "subjectRecordType": "claim-source",
        "subjectRecordId": "src-pn-ietf-bpsec"
      }
    },
    {
      "sourceId": "official-claim-source-src-pn-jpl-dsac",
      "sourceRecordType": "reference-source",
      "sourceFingerprint": "a2301c5d95dfe6321a96bddb31d69c3abc5c9f5dd6880287d858fe97b6383a03",
      "snapshot": {
        "title": "Working Overtime: NASA's Deep Space Atomic Clock Completes Mission",
        "url": "https://www.jpl.nasa.gov/news/working-overtime-nasas-deep-space-atomic-clock-completes-mission/",
        "checkedAt": null,
        "scopeNote": "Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion.",
        "subjectRecordType": "claim-source",
        "subjectRecordId": "src-pn-jpl-dsac"
      }
    }
  ],
  "packetFingerprint": "c143c856d4978f824701c6831dcc968482b4215f700f53579ca3d4d6155f9b0d"
}
