Packet identity

Packet ID
systems:cybersecurity
Packet SHA-256 identity
c143c856d4978f824701c6831dcc968482b4215f700f53579ca3d4d6155f9b0d
Corpus SHA-256 identity
8fa944604ca189f5a9216ca59f640ad2ca20972ad512f2f4970764716782e18d
Release ID
public-alpha-2026-07-26-research-visuals-r14
Source commit
3eb036fce3d711336c8c605625895e8a2e799ab0
Frozen corpus date
2026-07-25
Primary records
34
Reference sources
49

Questions and exclusions

Required questions

  1. Required question 1 (exact ID: question-1)
    Does each evidence basis, readiness level, confidence level, rationale, and locator match the frozen sources?
  2. Required question 2 (exact ID: question-2)
    Are dependencies, failure modes, precursors, unknowns, Earthside benefits, and the stop gate technically and ethically bounded?
  3. Required question 3 (exact ID: question-3)
    Which conclusion should be approved, revised, contested, rejected, or recused from at its current fingerprint?

Explicit exclusions

  • A system packet is not a complete spacecraft design, feasibility proof, safety case, or launch authorization.
  • Context sources do not become direct support unless the record says so with an exact locator and relation.

Requested controlled scopes: defensive-cyber-safety, information-science, security-assurance, systems-engineering

Frozen-evidence decision window: 365 days from the packet freeze. Not applicable to this packet family.

Complete primary record set

Every record below has one primary packet owner. Decisions must bind to the exact record and packet fingerprints; a changed lesson body, evidence grade, citation, locator, source snapshot, requirement, policy, release, or commit expires the old packet.

  1. system · cybersecurity

    Cybersecurity, software assurance & recovery

    Record fingerprint
    48a0199de1d45db9fdb9aad2b20fcd4d219be2d336a58c2b4b44921d27a82a21
    Minimum approvals
    1
    Required scope groups
    bounded-competence: defensive-cyber-safety, security-assurance
    High-consequence domains
    None under the named two-person rule
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    Slug
    cybersecurity
    Name
    Cybersecurity, software assurance & recovery
    Short Name
    Cyber resilience
    Index
    12
    Thesis
    Generation-ship security protects a civilization’s ability to operate, repair, govern, learn, and recover without an external rescuer—not merely its secrets.
    Current State
    1. Space, operational-technology, software-supply-chain, zero-trust, post-quantum, and cyber-resilience standards provide relevant but fragmented reference points; their existence does not establish integration or assurance.
    2. Secure-update patterns, attestation, delay-tolerant networking, formally assessed kernels, software bills of materials, and reproducible-build practices exist in different contexts. Availability does not establish compatibility, flight qualification, century maintenance, or safe integration.
    3. Within the public sources sampled for this foundation draft, we did not identify a generation-ship cybersecurity standard or a demonstrated century-scale cryptographic deployment.
    Unknowns
    1. Trust anchors, identity, secure time, revocation, incident command, threshold recovery, crypto-agile migration, anti-rollback, and archival signature interpretation must work locally after permanent loss of Earth.
    2. Insiders, collusion, governance capture, compromised suppliers, corrupted hardware, malicious maintenance, radiation faults, operator error, and generational loss of expertise must be addressed without turning safety monitoring into surveillance or political control.
    3. Onboard manufacturing makes malicious designs, poisoned toolchains, compromised metrology, counterfeit replacement parts, and configuration drift cyber-physical threats.
    Earth Benefits
    1. Disconnected trust fabrics, update airlocks, recovery vaults, and cyber ranges benefit critical infrastructure and remote industry.
    2. Crypto agility and toolchain escrow reduce obsolescence risk in medical, energy, transport, and public systems.
    Dependencies
    1. ai-autonomy
    2. communications-navigation
    3. manufacturing-isru
    Gate
    Mixed crews must repeatedly isolate a compromised zone, maintain life support, investigate locally, rebuild from known-good material, and rejoin safely.
    Sources
    1. Title
      NIST Cybersecurity Framework 2.0
      Kind
      Primary or institutional source
    2. Title
      NIST Cyber-Resilient Systems Engineering
      Kind
      Primary or institutional source
    3. Title
      NIST Operational Technology Security
      Kind
      Primary or institutional source
    4. Title
      NIST Secure Software Development Framework
      Kind
      Primary or institutional source
    Failure Modes
    1. A compromised build, spare, model, credential, or maintenance interface crosses isolation boundaries.
    2. Cryptography, identity, or recovery procedures become obsolete while privileged operators lose the ability to re-establish trust.
    Precursors
    1. Secure-by-design operational technology, reproducible builds, signed evidence graphs, and offline recovery media.
    2. Long-horizon incident exercises that include insider risk, degraded communications, hardware loss, and cryptographic migration.
  2. claim · claim-12-01

    Generation-ship security protects a civilization’s ability to operate, repair, govern, learn, and recover without an external rescuer—not merely its secrets.

    Record fingerprint
    908842da73f03771a9e09cc29bdc8e3863610f7ab9de665f452f153f7bb618b1
    Minimum approvals
    2
    Required scope groups
    domain-method: defensive-cyber-safety, governance-law-rights, security-assurance; rights-public-interest: affected-public-rights
    High-consequence domains
    cybersecurity, governance, life-support-continuity
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    claim-12-01
    System Slug
    cybersecurity
    Kind
    thesis
    Statement Ref
    Field
    thesis
    Statement
    Generation-ship security protects a civilization’s ability to operate, repair, govern, learn, and recover without an external rescuer—not merely its secrets.
    Statement Fingerprint
    c805232b478356847ba74782b6221b09ce6a1bc05c761188d34e892a9ddb771c
    Assessment
    Status
    Editorial assessed (exact value: editorial-assessed)
    Basis
    normative
    Readiness
    Early research (exact value: early-research)
    Confidence
    strong
    Rationale
    Current cyber-resiliency and incident-response guidance explicitly centers mission or organizational outcomes, anticipation, continued operation, recovery, and adaptation. NASA's Space Security Best Practices Guide strengthens the present space-mission context but does not support the claim's civilization-scale governance, learning, repair, or permanent-isolation extension. Extending the framing remains a normative systems proposal, not a demonstrated generation-ship implementation.
    Citations
    1. Source ID
      src-cr-nist-cyber-resilience-800160v2r1
      Locator
      Executive summary and sections 2.1 through 2.3 defining cyber resiliency as the ability to anticipate, withstand, recover from, and adapt to adverse conditions involving cyber resources.
      Relation
      Direct method (exact value: direct-method)
    2. Source ID
      src-cr-nist-incident-80061r3
      Locator
      CSF 2.0 Community Profile across Govern, Identify, Protect, Detect, Respond, and Recover, including preparation and improvement outside the immediate response phase.
      Relation
      Direct normative authority (exact value: direct-normative-authority)
    3. Source ID
      src-im-nist-ot-80082r3
      Locator
      Sections 2, 3, 5, and 6 on OT mission, safety, reliability, availability, physical effects, incident response, and recovery constraints.
      Relation
      Scope boundary (exact value: scope-boundary)
    4. Source ID
      src-cr-nasa-space-security-bpg-revb
      Locator
      Sections 1.1–1.2 on risk-based mission-success framing, space-vehicle and ground-segment scope, initial-baseline status, and the statement that the guide does not replace the System Security Plan.
      Relation
      Scope boundary (exact value: scope-boundary)
    Context Source IDs
    1. core-12-1
    2. core-12-2
    3. core-12-3
    4. core-12-4
    Editorial Provenance
    Status
    Substantive editorial review (exact value: substantive-editorial-review)
    Reviewers
    1. GShips Project editorial synthesis
    Conflicts
    1. Publisher intends to explore a commercial venture based on some GShips work; no entity, funding, customer, sponsor, or partner relationship with cited organizations is reported.
    What Would Change
    A reviewed alternative security objective that better preserves essential service, repair, learning, legitimate governance, and local recovery could replace this framing. Repeated closed-habitat tests showing that confidentiality-centered controls alone preserve those outcomes would weaken it; repeated failures of mission-centered designs would require narrowing or redesign.
    High Consequence
    1. cybersecurity
    2. life-support-continuity
    3. governance
  3. claim · claim-12-02

    Space-sector guidance and protocol-security reports, operational-technology, software-supply-chain, zero-trust, post-quantum, and cyber-resilience standards provide relevant but fragmented reference points; their existence does not establish integration or assurance.

    Record fingerprint
    0f49699074aad1bdc4026a7e08cecd517f96beb614fa4055762c508de9fa31fc
    Minimum approvals
    2
    Required scope groups
    domain-method: defensive-cyber-safety, dual-use-risk, security-assurance; rights-public-interest: affected-public-rights
    High-consequence domains
    cybersecurity, dual-use, spacecraft-safety
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    claim-12-02
    System Slug
    cybersecurity
    Kind
    current state
    Statement Ref
    Field
    currentState
    Index
    0
    Statement
    Space-sector guidance and protocol-security reports, operational-technology, software-supply-chain, zero-trust, post-quantum, and cyber-resilience standards provide relevant but fragmented reference points; their existence does not establish integration or assurance.
    Statement Fingerprint
    dee7d9059c1d19cbe5f79d789f2e9c600c7a847341eebf8b9c2ad004a902cde2
    Assessment
    Status
    Editorial assessed (exact value: editorial-assessed)
    Basis
    observed
    Readiness
    Major scale up (exact value: major-scale-up)
    Confidence
    strong
    Rationale
    Authoritative publications separately address OT security, zero trust, cyber-resilient systems, secure development, supply chains, and post-quantum cryptography. NASA's BPG is guidance, CCSDS 350.0-G-3 is an informational report, and the CryptoLib record is an abstract-only implementation report. Their different authorities, scopes, assumptions, and system boundaries support the claim that reference points exist but do not by themselves establish compatibility, integration, conformance, or assurance for a closed habitat.
    Citations
    1. Source ID
      src-im-nist-ot-80082r3
      Locator
      Sections 2 and 3 on operational-technology architectures, safety and availability constraints, threats, and risk differences from ordinary information systems.
      Relation
      Direct normative authority (exact value: direct-normative-authority)
    2. Source ID
      src-cr-nist-zero-trust-800207
      Locator
      Sections 2 and 3 on zero-trust tenets and logical components, and section 7 on threats; enterprise scope is explicit.
      Relation
      Scope boundary (exact value: scope-boundary)
    3. Source ID
      src-cr-nist-ssdf-800218
      Locator
      Table 1 practices PO, PS, PW, and RV for secure software development and vulnerability response.
      Relation
      Direct normative authority (exact value: direct-normative-authority)
    4. Source ID
      src-cr-nist-fips203-mlkem
      Locator
      Sections 1 through 7 defining ML-KEM purpose, parameter sets, algorithms, and implementation requirements.
      Relation
      Direct normative authority (exact value: direct-normative-authority)
    5. Source ID
      src-cr-nasa-std-1006a
      Locator
      Active NASA mission-protection requirements; applicability does not establish implementation or assurance for any particular architecture.
      Relation
      Direct normative authority (exact value: direct-normative-authority)
    6. Source ID
      src-cr-nasa-space-security-bpg-revb
      Locator
      Sections 1.1–1.2 and the principles/control mappings: NASA describes mission-security guidance and an initial starting point, not a validated integrated architecture.
      Relation
      Direct observation (exact value: direct-observation)
    7. Source ID
      src-cr-ccsds-350-0-g-3
      Locator
      Foreword, document status, and Section 1 purpose and scope: protocol-layer security options classified as a Green Book informational report, not a Recommended Standard.
      Relation
      Scope boundary (exact value: scope-boundary)
    8. Source ID
      src-cr-nasa-cryptolib-2023
      Locator
      NTRS abstract paragraphs 2–4: the project aims at CCSDS SDLS compliance and reports selected TC, TM, and AOS cryptography functions; the source is abstract-only and reports development status rather than conformance.
      Relation
      Direct observation (exact value: direct-observation)
    Context Source IDs
    1. core-12-1
    2. core-12-2
    3. core-12-3
    4. core-12-4
    Editorial Provenance
    Status
    Substantive editorial review (exact value: substantive-editorial-review)
    Reviewers
    1. GShips Project editorial synthesis
    Conflicts
    1. Publisher intends to explore a commercial venture based on some GShips work; no entity, funding, customer, sponsor, or partner relationship with cited organizations is reported.
    What Would Change
    A published, independently reviewed architecture that maps these standards into one representative closed-habitat assurance case, resolves conflicting assumptions, and passes integrated safety and recovery tests would change the fragmentation conclusion. Merely citing more standards would not.
    High Consequence
    1. cybersecurity
    2. spacecraft-safety
    3. dual-use
  4. claim · claim-12-03

    Secure firmware-update patterns, platform recovery, software-component inventories, bundle-layer security for disrupted networking, and a publicly described CCSDS-oriented space-data-link cryptography library exist in different contexts. Availability does not establish compatibility, conformance, flight qualification, safe integration, or century maintenance.

    Record fingerprint
    6055efdd9314736b322ecafce96268e59c3ddc2c7874b92f43b11b7494689e92
    Minimum approvals
    2
    Required scope groups
    domain-method: defensive-cyber-safety, dual-use-risk, security-assurance; rights-public-interest: affected-public-rights
    High-consequence domains
    cybersecurity, dual-use, software-supply-chain, spacecraft-safety
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    claim-12-03
    System Slug
    cybersecurity
    Kind
    current state
    Statement Ref
    Field
    currentState
    Index
    1
    Statement
    Secure firmware-update patterns, platform recovery, software-component inventories, bundle-layer security for disrupted networking, and a publicly described CCSDS-oriented space-data-link cryptography library exist in different contexts. Availability does not establish compatibility, conformance, flight qualification, safe integration, or century maintenance.
    Statement Fingerprint
    f34f71c04e7de1ae413c8ffe6b8bdb1238a23f2ea53cf1e06528b94325e93c4d
    Assessment
    Status
    Editorial assessed (exact value: editorial-assessed)
    Basis
    observed
    Readiness
    Early research (exact value: early-research)
    Confidence
    supported
    Rationale
    The cited sources establish secure-firmware-update architecture, platform protect-detect-recover mechanisms, software-component transparency, and bundle-layer security. The NTRS abstract publicly describes an actively developed CCSDS-oriented cryptography library but does not establish conformance, secure implementation, deployment, or flight qualification. The sources do not establish compatibility among components, safe key governance, integration, or century maintenance.
    Citations
    1. Source ID
      src-cr-ietf-rfc9019-suit
      Locator
      Sections 3 through 7 and 10 on update roles, authenticated manifests, target matching, sequence controls, dependencies, interruption, installation, and recovery.
      Relation
      Direct normative authority (exact value: direct-normative-authority)
    2. Source ID
      src-cr-nist-firmware-800193
      Locator
      Sections 3 and 4 on roots of trust and mechanisms to protect, detect unauthorized change, and securely recover platform firmware and critical data.
      Relation
      Scope boundary (exact value: scope-boundary)
    3. Source ID
      src-cr-nist-ssdf-800218
      Locator
      Practices PS.1 through PS.3 and PW.4 through PW.9 on protecting code, verifying third-party components, review, testing, secure defaults, and release integrity.
      Relation
      Direct normative authority (exact value: direct-normative-authority)
    4. Source ID
      src-cr-cisa-sbom
      Locator
      SBOM definition, ecosystem roles, use cases, and current minimum-elements materials.
      Relation
      Direct observation (exact value: direct-observation)
    5. Source ID
      src-pn-ietf-bpsec
      Locator
      Sections defining integrity and confidentiality security blocks for Bundle Protocol in disrupted and delay-tolerant networks.
      Relation
      Direct normative authority (exact value: direct-normative-authority)
    6. Source ID
      src-cr-ccsds-350-0-g-3
      Locator
      Section 1 and protocol-layer application discussion; the Green Book is an informational scope boundary, not proof that CryptoLib conforms.
      Relation
      Scope boundary (exact value: scope-boundary)
    7. Source ID
      src-cr-nasa-cryptolib-2023
      Locator
      Abstract paragraphs 2–4: active-development and aims-to-comply language plus selected TC, TM, and AOS scope; abstract-only record.
      Relation
      Direct observation (exact value: direct-observation)
    Context Source IDs
    1. core-12-1
    2. core-12-2
    3. core-12-3
    4. core-12-4
    Editorial Provenance
    Status
    Substantive editorial review (exact value: substantive-editorial-review)
    Reviewers
    1. GShips Project editorial synthesis
    Conflicts
    1. Publisher intends to explore a commercial venture based on some GShips work; no entity, funding, customer, sponsor, or partner relationship with cited organizations is reported.
    What Would Change
    A representative integrated test combining secure update, platform recovery, disrupted networking, transparent software composition, space-data-link cryptography, old hardware, power interruption, key loss or compromise, and verified rollback would raise readiness. A public conformance result and operational deployment would strengthen the CryptoLib example. Evidence of incompatibility, unsafe recovery, unmaintainable cryptography, or correlated trust failure would narrow candidate architectures.
    High Consequence
    1. cybersecurity
    2. software-supply-chain
    3. spacecraft-safety
    4. dual-use
  5. claim · claim-12-04

    Within the public sources sampled for this foundation draft, we did not identify a generation-ship cybersecurity standard or a demonstrated century-scale cryptographic deployment.

    Record fingerprint
    1f2f998d50f9608459ee4d3da4ac355a5bf83f8c7d328e5d931ade7d5e4ec478
    Minimum approvals
    2
    Required scope groups
    domain-method: defensive-cyber-safety, security-assurance; rights-public-interest: affected-public-rights
    High-consequence domains
    cryptography, cybersecurity, spacecraft-safety
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    claim-12-04
    System Slug
    cybersecurity
    Kind
    current state
    Statement Ref
    Field
    currentState
    Index
    2
    Statement
    Within the public sources sampled for this foundation draft, we did not identify a generation-ship cybersecurity standard or a demonstrated century-scale cryptographic deployment.
    Statement Fingerprint
    3f1223a76b93a7df07fdda1de97e20db6cb6a61d43dbc77e993cd336bd4414fd
    Assessment
    Status
    Editorial assessed (exact value: editorial-assessed)
    Basis
    observed
    Readiness
    No known path (exact value: no-known-path)
    Confidence
    supported
    Rationale
    The bounded official corpus contains current standards and guidance for cyber resilience, key management, algorithm transition, and post-quantum primitives, each scoped to present systems and transitions. It contains neither a generation-ship cybersecurity standard nor a demonstrated century-scale cryptographic deployment. This is a transparent bounded-corpus finding, not proof that no relevant document exists anywhere.
    Citations
    1. Source ID
      src-cr-nist-cyber-resilience-800160v2r1
      Locator
      Scope, executive summary, and chapters 2 and 3; general systems-security engineering context without a generation-ship profile.
      Relation
      Direct observation (exact value: direct-observation)
    2. Source ID
      src-cr-nist-key-management-80057p1r5
      Locator
      Sections 5 through 8 on algorithms, key lifecycle, protection periods, compromise, backup, recovery, archival, and destruction.
      Relation
      Context only (exact value: context-only)
    3. Source ID
      src-cr-nist-crypto-agility-cswp39u1
      Locator
      Definition, discovery and inventory, strategic planning, protocol and application transitions, operational mechanisms, trade-offs, and areas for further work.
      Relation
      Context only (exact value: context-only)
    4. Source ID
      src-cr-nist-fips204-mldsa
      Locator
      Sections 1 through 7 defining ML-DSA, approved parameter sets, and implementation requirements; no century-deployment claim.
      Relation
      Scope boundary (exact value: scope-boundary)
    Context Source IDs
    1. core-12-1
    2. core-12-2
    3. core-12-3
    4. core-12-4
    Editorial Provenance
    Status
    Substantive editorial review (exact value: substantive-editorial-review)
    Reviewers
    1. GShips Project editorial synthesis
    Conflicts
    1. Publisher intends to explore a commercial venture based on some GShips work; no entity, funding, customer, sponsor, or partner relationship with cited organizations is reported.
    What Would Change
    Discovery of an authoritative generation-ship cybersecurity standard would falsify the first bounded finding. Independently audited cryptographic operation over a century, including algorithm migration, key succession, archival validation, old hardware, and compromise recovery, would change the second; a paper lifetime estimate would not.
    High Consequence
    1. cybersecurity
    2. cryptography
    3. spacecraft-safety
  6. claim · claim-12-05

    Trust anchors, identity, secure time, revocation, incident command, threshold recovery, crypto-agile migration, anti-rollback, and archival signature interpretation must work locally after permanent loss of Earth.

    Record fingerprint
    2811cbe867ae12c3b3d54f9da45439d26535ec4349f41ae4a7cb36eb37ea26a1
    Minimum approvals
    2
    Required scope groups
    domain-method: defensive-cyber-safety, governance-law-rights, security-assurance; rights-public-interest: affected-public-rights
    High-consequence domains
    cybersecurity, governance
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    claim-12-05
    System Slug
    cybersecurity
    Kind
    unknown
    Statement Ref
    Field
    unknowns
    Index
    0
    Statement
    Trust anchors, identity, secure time, revocation, incident command, threshold recovery, crypto-agile migration, anti-rollback, and archival signature interpretation must work locally after permanent loss of Earth.
    Statement Fingerprint
    9889918cc748c4b0b6cfa5f73d5debe30ebb19f2d08bbaf210e1d531d9552e19
    Assessment
    Status
    Editorial assessed (exact value: editorial-assessed)
    Basis
    normative
    Readiness
    Early research (exact value: early-research)
    Confidence
    supported
    Rationale
    Bundle security, archival standards, atomic clocks, and current operational security practices address parts of the requirement. No reviewed evidence demonstrates crypto-agile identity, secure-time, revocation, threshold recovery, anti-rollback, incident command, and archival interpretation as one locally recoverable multigenerational institution.
    Citations
    1. Source ID
      src-pn-ietf-bpsec
      Locator
      Security-block processing, integrity and confidentiality services, threat model, and key-management exclusions.
      Relation
      Direct normative authority (exact value: direct-normative-authority)
    2. Source ID
      src-pn-ccsds-oais
      Locator
      Representation information, preservation planning, archive management, access, and designated-community requirements.
      Relation
      Direct normative authority (exact value: direct-normative-authority)
    3. Source ID
      src-pn-jpl-dsac
      Locator
      Space atomic-clock stability result, mission duration, and bounded technology-demonstration scope.
      Relation
      Direct demonstration (exact value: direct-demonstration)
    Context Source IDs
    1. core-12-1
    2. core-12-2
    3. core-12-3
    4. core-12-4
    Editorial Provenance
    Status
    Substantive editorial review (exact value: substantive-editorial-review)
    Reviewers
    1. GShips Project editorial synthesis
    Conflicts
    1. Publisher intends to explore a commercial venture based on some GShips work.
    What Would Change
    A long-duration red-team and succession program that repeatedly recovers clocks, identities, keys, revocation state, archives, commands, and cryptographic migrations without Earth, original experts, or one trusted implementation would raise readiness.
    High Consequence
    1. cybersecurity
    2. governance
  7. claim · claim-12-06

    Insiders, collusion, governance capture, compromised suppliers, corrupted hardware, malicious maintenance, radiation faults, operator error, and generational loss of expertise must be addressed without turning safety monitoring into surveillance or political control.

    Record fingerprint
    e661cc2789a8cd078b10a5fa6f5f4bb267c1dcdcc4156a6fd1870fa857a41db2
    Minimum approvals
    2
    Required scope groups
    domain-method: defensive-cyber-safety, governance-law-rights, security-assurance; rights-public-interest: affected-public-rights
    High-consequence domains
    cybersecurity, governance, human-rights, life-support-continuity, privacy
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    claim-12-06
    System Slug
    cybersecurity
    Kind
    unknown
    Statement Ref
    Field
    unknowns
    Index
    1
    Statement
    Insiders, collusion, governance capture, compromised suppliers, corrupted hardware, malicious maintenance, radiation faults, operator error, and generational loss of expertise must be addressed without turning safety monitoring into surveillance or political control.
    Statement Fingerprint
    214d781b1e11d13c5cdd7ff5867c7ed4cdbec323c647bf0dd76fcdab69f548b6
    Assessment
    Status
    Editorial assessed (exact value: editorial-assessed)
    Basis
    normative
    Readiness
    Early research (exact value: early-research)
    Confidence
    supported
    Rationale
    Current OT, supply-chain, security-control, and adversarial-AI guidance supports the inclusion of insiders, suppliers, hardware and software corruption, maintenance access, operator error, and poisoned models. Governance capture, generational expertise loss, and limits on surveillance are essential normative extensions for a closed society; the cited technical sources do not resolve their constitutional implementation.
    Citations
    1. Source ID
      src-cr-nist-scrm-800161r1u1
      Locator
      Executive summary and sections 2 and 3 on malicious functionality, counterfeit, tampering, poor development and manufacturing practice, supplier visibility, and multilevel lifecycle risk.
      Relation
      Direct normative authority (exact value: direct-normative-authority)
    2. Source ID
      src-im-nist-ot-80082r3
      Locator
      Threat and vulnerability sections covering insiders, maintenance, remote access, supply chain, configuration, operator error, availability, safety, and physical consequences.
      Relation
      Direct normative authority (exact value: direct-normative-authority)
    3. Source ID
      src-cr-nist-controls-80053r5
      Locator
      Personnel Security, Access Control, Audit and Accountability, Privacy, Supply Chain Risk Management, Maintenance, Incident Response, and System Integrity control families.
      Relation
      Direct normative authority (exact value: direct-normative-authority)
    4. Source ID
      src-cr-nist-aml-100-2e2025
      Locator
      Taxonomy chapters covering predictive- and generative-AI poisoning, evasion, privacy, misuse, lifecycle stages, attacker capabilities, and mitigation limitations.
      Relation
      Direct normative authority (exact value: direct-normative-authority)
    Context Source IDs
    1. core-12-1
    2. core-12-2
    3. core-12-3
    4. core-12-4
    Editorial Provenance
    Status
    Substantive editorial review (exact value: substantive-editorial-review)
    Reviewers
    1. GShips Project editorial synthesis
    Conflicts
    1. Publisher intends to explore a commercial venture based on some GShips work; no entity, funding, customer, sponsor, or partner relationship with cited organizations is reported.
    What Would Change
    Long-duration habitat trials with independent civil-rights review could identify a narrower threat set or controls that provide equivalent safety with less monitoring. Evidence that proposed telemetry, identity, or emergency powers predictably enable coercion or suppress truthful reporting should remove or redesign those controls, even if they improve technical detection.
    High Consequence
    1. cybersecurity
    2. governance
    3. privacy
    4. human-rights
    5. life-support-continuity
  8. claim · claim-12-07

    Onboard manufacturing makes malicious designs, poisoned toolchains, compromised metrology, counterfeit replacement parts, and configuration drift cyber-physical threats.

    Record fingerprint
    aa41b5d69f1e2cb946f156453cc5e43165f992ffba714ec0b1562413e4751e5c
    Minimum approvals
    2
    Required scope groups
    domain-method: defensive-cyber-safety, security-assurance; rights-public-interest: affected-public-rights
    High-consequence domains
    cybersecurity, spacecraft-safety, supply-chain
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    claim-12-07
    System Slug
    cybersecurity
    Kind
    unknown
    Statement Ref
    Field
    unknowns
    Index
    2
    Statement
    Onboard manufacturing makes malicious designs, poisoned toolchains, compromised metrology, counterfeit replacement parts, and configuration drift cyber-physical threats.
    Statement Fingerprint
    652aecb33bcd4c10a3c944775abc632ed556d9e8ee441a6b895d6cdfe4481ec3
    Assessment
    Status
    Editorial assessed (exact value: editorial-assessed)
    Basis
    modeled
    Readiness
    Early research (exact value: early-research)
    Confidence
    supported
    Rationale
    Manufacturing records, controller software, toolpaths, process limits, metrology corrections, and acceptance criteria directly govern physical outputs. Current OT security and NASA manufacturing assurance controls support the threat pathways, while a generation-scale adversarial factory test has not been performed.
    Citations
    1. Source ID
      src-im-nist-ot-80082r3
      Locator
      Sections on manufacturing OT, supply-chain compromise, unauthorized change, maintenance access, segmentation, integrity, and recovery.
      Relation
      Direct normative authority (exact value: direct-normative-authority)
    2. Source ID
      src-im-nasa-std-6030
      Locator
      Requirements covering authorized process specifications, feedstock, machine qualification, digital build files, configuration control, inspection, and acceptance.
      Relation
      Direct normative authority (exact value: direct-normative-authority)
    3. Source ID
      src-im-nasa-metrology-873912
      Locator
      Requirements for selection, calibration, control, traceability, and use of measuring and test equipment affecting safety or mission success.
      Relation
      Direct method (exact value: direct-method)
    4. Source ID
      src-im-nasa-eee-873910
      Locator
      Scope and requirements for electronic-part acquisition, traceability, testing, handling, storage, application, and supply risk.
      Relation
      Direct normative authority (exact value: direct-normative-authority)
    Context Source IDs
    1. core-12-1
    2. core-12-2
    3. core-12-3
    4. core-12-4
    Editorial Provenance
    Status
    Substantive editorial review (exact value: substantive-editorial-review)
    Reviewers
    1. GShips Project editorial synthesis
    Conflicts
    1. Publisher intends to explore a commercial venture based on some GShips work.
    What Would Change
    A representative cyber-physical factory exercise that controls unauthorized designs and process changes, detects poisoned tools and calibration, rejects counterfeit parts, restores a known-good configuration, and measures residual defects would change confidence and required controls.
    High Consequence
    1. cybersecurity
    2. supply-chain
    3. spacecraft-safety
  9. claim · claim-12-08

    Disconnected trust fabrics, update airlocks, recovery vaults, and cyber ranges benefit critical infrastructure and remote industry.

    Record fingerprint
    cf9e9af24876befe4386e5d20c5bd3940c82a2f55d410ae762b76cc43357ca22
    Minimum approvals
    2
    Required scope groups
    domain-method: defensive-cyber-safety, dual-use-risk, security-assurance; rights-public-interest: affected-public-rights
    High-consequence domains
    critical-infrastructure, cybersecurity, dual-use
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    claim-12-08
    System Slug
    cybersecurity
    Kind
    earth benefit
    Statement Ref
    Field
    earthBenefits
    Index
    0
    Statement
    Disconnected trust fabrics, update airlocks, recovery vaults, and cyber ranges benefit critical infrastructure and remote industry.
    Statement Fingerprint
    3091af12d5127935922a8d65792b3d50cbee8d89257ecb9341ecfe8844f77279
    Assessment
    Status
    Editorial assessed (exact value: editorial-assessed)
    Basis
    proposed
    Readiness
    Early research (exact value: early-research)
    Confidence
    tentative
    Rationale
    Disconnected recovery, segmented operation, controlled updates, firmware recovery, and incident exercises are relevant to current critical infrastructure and remote operations. The specific bundle described by the claim has not been evaluated as one intervention, so Earthside benefit is plausible but not established net of cost, complexity, workload, accessibility, and governance risk.
    Citations
    1. Source ID
      src-cr-nist-cyber-resilience-800160v2r1
      Locator
      Cyber-resiliency techniques and approaches including segmentation, diversity, redundancy, substantiated integrity, predefined segmentation, and recovery.
      Relation
      Direct normative authority (exact value: direct-normative-authority)
    2. Source ID
      src-cr-nist-firmware-800193
      Locator
      Protect, detect, and recover model for platform firmware and critical data, including roots of trust.
      Relation
      Context only (exact value: context-only)
    3. Source ID
      src-cr-nist-incident-80061r3
      Locator
      CSF 2.0 profile recommendations for preparation, detection, response, recovery, communications, and improvement.
      Relation
      Direct normative authority (exact value: direct-normative-authority)
    4. Source ID
      src-im-nist-ot-80082r3
      Locator
      OT architectures, segmentation, incident response, recovery, safety, and availability constraints relevant to remote and critical industry.
      Relation
      Context only (exact value: context-only)
    Context Source IDs
    1. core-12-1
    2. core-12-2
    3. core-12-3
    4. core-12-4
    Editorial Provenance
    Status
    Substantive editorial review (exact value: substantive-editorial-review)
    Reviewers
    1. GShips Project editorial synthesis
    Conflicts
    1. Publisher intends to explore a commercial venture based on some GShips work; no entity, funding, customer, sponsor, or partner relationship with cited organizations is reported.
    What Would Change
    Controlled deployments in remote utilities, hospitals, industrial sites, or isolated research stations should measure safe-service continuity, recovery time, false isolation, operator burden, accessibility, privacy impact, and total cost against a baseline. Consistent harm or no benefit would weaken or reverse the Earth-benefit claim.
    High Consequence
    1. cybersecurity
    2. critical-infrastructure
    3. dual-use
  10. claim · claim-12-09

    Crypto agility and toolchain escrow reduce obsolescence risk in medical, energy, transport, and public systems.

    Record fingerprint
    4c3588aab47e1175acc7a32a66fd16e23f01df3fd603f3d4005e2e5503935290
    Minimum approvals
    2
    Required scope groups
    domain-method: defensive-cyber-safety, security-assurance; rights-public-interest: affected-public-rights
    High-consequence domains
    critical-infrastructure, cybersecurity, software-supply-chain
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    claim-12-09
    System Slug
    cybersecurity
    Kind
    earth benefit
    Statement Ref
    Field
    earthBenefits
    Index
    1
    Statement
    Crypto agility and toolchain escrow reduce obsolescence risk in medical, energy, transport, and public systems.
    Statement Fingerprint
    d727ace64c3dbae511612cfdaa6d61d9dd6a06428fee0a02ce3b3c311bcd8d36
    Assessment
    Status
    Editorial assessed (exact value: editorial-assessed)
    Basis
    proposed
    Readiness
    Major scale up (exact value: major-scale-up)
    Confidence
    supported
    Rationale
    NIST guidance directly treats algorithm replacement, cryptographic inventories, key lifecycle, secure development, supply-chain visibility, and transition continuity as current risk-management needs. Preserving build tools, source, specifications, and recovery knowledge as an escrowed local capability is a systems inference rather than a directly demonstrated cross-sector program.
    Citations
    1. Source ID
      src-cr-nist-crypto-agility-cswp39u1
      Locator
      Sections on cryptographic discovery and inventory, strategic planning, protocols, applications, operational mechanisms, transition dependencies, trade-offs, and metrics.
      Relation
      Direct normative authority (exact value: direct-normative-authority)
    2. Source ID
      src-cr-nist-key-management-80057p1r5
      Locator
      Key-management lifecycle, cryptoperiods, compromise, backup, recovery, archival, and transition-related protection requirements.
      Relation
      Direct normative authority (exact value: direct-normative-authority)
    3. Source ID
      src-cr-nist-ssdf-800218
      Locator
      Practices PO.1 through PO.5, PS.1 through PS.3, PW.4 through PW.9, and RV.1 through RV.3 for organizational preparation, protected artifacts, secure production, and vulnerability response.
      Relation
      Direct normative authority (exact value: direct-normative-authority)
    4. Source ID
      src-cr-nist-scrm-800161r1u1
      Locator
      Lifecycle and supplier-risk guidance addressing provenance, reduced visibility, dependencies, maintenance, and product or service continuity.
      Relation
      Context only (exact value: context-only)
    Context Source IDs
    1. core-12-1
    2. core-12-2
    3. core-12-3
    4. core-12-4
    Editorial Provenance
    Status
    Substantive editorial review (exact value: substantive-editorial-review)
    Reviewers
    1. GShips Project editorial synthesis
    Conflicts
    1. Publisher intends to explore a commercial venture based on some GShips work; no entity, funding, customer, sponsor, or partner relationship with cited organizations is reported.
    What Would Change
    Longitudinal evidence from medical, energy, transport, or public systems should compare migration time, outage, stranded assets, security regressions, and recovery with and without maintained inventories and locally recoverable toolchains. Evidence that escrow increases compromise or obsolescence risk more than it reduces transition risk would narrow the claim.
    High Consequence
    1. cybersecurity
    2. critical-infrastructure
    3. software-supply-chain
  11. claim · claim-12-10

    Mixed crews must repeatedly isolate a compromised zone, maintain life support, investigate locally, rebuild from known-good material, and rejoin safely.

    Record fingerprint
    718e87306ab83c20b2c477e928406ce5697e01b1a5b64ab9cde6d6fbcbe148be
    Minimum approvals
    2
    Required scope groups
    domain-method: defensive-cyber-safety, dual-use-risk, governance-law-rights, security-assurance; rights-public-interest: affected-public-rights
    High-consequence domains
    cybersecurity, dual-use, governance, life-support-continuity, spacecraft-safety
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    claim-12-10
    System Slug
    cybersecurity
    Kind
    decision gate
    Statement Ref
    Field
    gate
    Statement
    Mixed crews must repeatedly isolate a compromised zone, maintain life support, investigate locally, rebuild from known-good material, and rejoin safely.
    Statement Fingerprint
    4f05154a910bd1893b5d593a3436968f8a69ec03158413dd31735a0f241feddc
    Assessment
    Status
    Editorial assessed (exact value: editorial-assessed)
    Basis
    normative
    Readiness
    Early research (exact value: early-research)
    Confidence
    supported
    Rationale
    Current incident-response, OT, cyber-resiliency, and recovery guidance supports preparation, isolation, minimum-safe operation, known-good restoration, testing, and measured recovery. Requiring repeated mixed-crew exercises without Earth is a GShips safety gate; no cited source demonstrates that integrated capability in a generation-scale habitat.
    Citations
    1. Source ID
      src-cr-nist-incident-80061r3
      Locator
      Respond and Recover profile outcomes and supporting Govern, Identify, Protect, and Detect recommendations for preparation, analysis, mitigation, communication, and improvement.
      Relation
      Direct normative authority (exact value: direct-normative-authority)
    2. Source ID
      src-cr-nist-recovery-800184
      Locator
      Sections 2 through 4 on recovery planning, playbooks, testing, metrics, restoration, and lessons learned.
      Relation
      Direct method (exact value: direct-method)
    3. Source ID
      src-cr-nist-cyber-resilience-800160v2r1
      Locator
      Cyber-resiliency goals and techniques for withstanding, recovering, adapting, segmentation, diversity, redundancy, and substantiated integrity.
      Relation
      Direct method (exact value: direct-method)
    4. Source ID
      src-im-nist-ot-80082r3
      Locator
      Sections on OT safety and availability constraints, incident response, contingency planning, recovery, architectures, and segmentation.
      Relation
      Scope boundary (exact value: scope-boundary)
    Context Source IDs
    1. core-12-1
    2. core-12-2
    3. core-12-3
    4. core-12-4
    Editorial Provenance
    Status
    Substantive editorial review (exact value: substantive-editorial-review)
    Reviewers
    1. GShips Project editorial synthesis
    Conflicts
    1. Publisher intends to explore a commercial venture based on some GShips work; no entity, funding, customer, sponsor, or partner relationship with cited organizations is reported.
    What Would Change
    An independently reviewed assurance protocol demonstrating equal or stronger coverage could replace this gate. To satisfy it, changing mixed crews must repeatedly maintain declared minimum safe service while isolated, preserve evidence and rights, rebuild from local known-good material, attest with independent physical checks, reconnect in stages, and recover after injected faults without remote support.
    High Consequence
    1. cybersecurity
    2. spacecraft-safety
    3. life-support-continuity
    4. governance
    5. dual-use
  12. claim-source · src-cr-ccsds-350-0-g-3

    The Application of Security to CCSDS Protocols (opens external site in a new tab)

    Record fingerprint
    44f5371a3c01028d94ba87eb2c3367b47b781a3fe2f7de8e0bb5c7486278d8fb
    Minimum approvals
    1
    Required scope groups
    bounded-competence: information-science
    High-consequence domains
    None under the named two-person rule
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    src-cr-ccsds-350-0-g-3
    Title
    The Application of Security to CCSDS Protocols
    Authors
    1. Consultative Committee for Space Data Systems
    Publisher
    CCSDS
    Year
    2019
    Kind
    Ccsds informational green book (exact value: ccsds-informational-green-book)
    Checked At
    2026-07-26
    Version
    CCSDS 350.0-G-3, Issue 3
    Scope Note
    Consensus informational report on security concepts, mechanisms, implementation options, and effects on CCSDS services, primarily for space-ground and ground-space links. The report explicitly is not a CCSDS Recommended Standard and excludes detailed security-analysis and risk-assessment methods.
  13. claim-source · src-cr-cisa-sbom

    Software Bill of Materials (opens external site in a new tab)

    Record fingerprint
    d551139e9329c0f04e2480582f3dd9123e7d717b8bfedf5cb6141bc087053d16
    Minimum approvals
    1
    Required scope groups
    bounded-competence: information-science
    High-consequence domains
    None under the named two-person rule
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    src-cr-cisa-sbom
    Title
    Software Bill of Materials
    Authors
    1. Cybersecurity and Infrastructure Security Agency
    Publisher
    CISA
    Year
    2026
    Kind
    Government software transparency resource (exact value: government-software-transparency-resource)
    Checked At
    2026-07-25
    Scope Note
    Official SBOM definition, ecosystem roles, use cases, community resources, and minimum-elements guidance; an SBOM is component evidence rather than proof of safety.
  14. claim-source · src-cr-ietf-rfc9019-suit

    A Firmware Update Architecture for Internet of Things (opens external site in a new tab)

    Record fingerprint
    f89082ee842c244fde0169bd864fb0a0b2e4390d2b8bda120bbe1fcb414b62e7
    Minimum approvals
    1
    Required scope groups
    bounded-competence: information-science
    High-consequence domains
    None under the named two-person rule
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    src-cr-ietf-rfc9019-suit
    Title
    A Firmware Update Architecture for Internet of Things
    Authors
    1. Brendan Moran
    2. Hannes Tschofenig
    3. David Brown
    4. Milton Meriac
    Publisher
    IETF
    Year
    2021
    Kind
    Ietf informational architecture (exact value: ietf-informational-architecture)
    Checked At
    2026-07-25
    Scope Note
    Informational IETF architecture for authenticated firmware manifests, stakeholder separation, target matching, sequence control, dependencies, interruption tolerance, and recovery.
  15. claim-source · src-cr-nasa-cryptolib-2023

    The State of CryptoLib – The Open-Source Satellite Cryptography Library (opens external site in a new tab)

    Record fingerprint
    841fcaee2944c6aef6a4e4b5275ddaaea99533977c6de713671c428d94b6998c
    Minimum approvals
    1
    Required scope groups
    bounded-competence: information-science
    High-consequence domains
    None under the named two-person rule
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    src-cr-nasa-cryptolib-2023
    Title
    The State of CryptoLib – The Open-Source Satellite Cryptography Library
    Authors
    1. D. Cody Cutright
    2. Scott A. Zemerick
    3. Robert J. Brown
    4. John P. Lucas
    5. Justin R. Morris
    Publisher
    NASA Technical Reports Server
    Year
    2023
    Kind
    Nasa conference abstract (exact value: nasa-conference-abstract)
    Checked At
    2026-07-26
    Scope Note
    Professionally reviewed conference record distributed in 2023; NTRS marks the available record onlyAbstract=true. The abstract describes an actively developed open-source C library that aims to be CCSDS Space Data Link Security compliant and reports selected Telecommand, Telemetry, and Advanced Orbiting Systems encryption and decryption functions. It does not establish CCSDS conformance, secure implementation, operational deployment, flight qualification, key-management assurance, or long-duration maintenance.
  16. claim-source · src-cr-nasa-space-security-bpg-revb

    Space Security: Best Practices Guide (opens external site in a new tab)

    Record fingerprint
    49def0ff9598b6f4abebd7c72c8abe70acd2cba861d8cb9407389b95a0ef3d94
    Minimum approvals
    1
    Required scope groups
    bounded-competence: information-science
    High-consequence domains
    None under the named two-person rule
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    src-cr-nasa-space-security-bpg-revb
    Title
    Space Security: Best Practices Guide
    Authors
    1. National Aeronautics and Space Administration
    Publisher
    NASA
    Year
    2024
    Kind
    Nasa space security guidance (exact value: nasa-space-security-guidance)
    Checked At
    2026-07-26
    Version
    Revision B
    Document Date
    2024-01-19
    Scope Note
    Public NASA guidance translating selected NIST SP 800-53 controls into space-vehicle and ground-segment mission language. It is a risk-based starting point and expressly does not replace required plans or establish a certified architecture, flight qualification, or long-duration assurance.
  17. claim-source · src-cr-nasa-std-1006a

    Space System Protection Standard (opens external site in a new tab)

    Record fingerprint
    21bc08c8476b722c9011a875a0feeef60390048860f419d797f96be3a5cf998a
    Minimum approvals
    1
    Required scope groups
    bounded-competence: information-science
    High-consequence domains
    None under the named two-person rule
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    src-cr-nasa-std-1006a
    Title
    Space System Protection Standard
    Authors
    1. National Aeronautics and Space Administration
    Publisher
    NASA Technical Standards System
    Year
    2022
    Kind
    Active nasa mandatory standard (exact value: active-nasa-mandatory-standard)
    Checked At
    2026-07-26
    Version
    A
    Document Date
    2022-07-15
    Status
    ACTIVE
    Review Due
    2027-07-15
    Scope Note
    Active Agency-level protection requirements intended to make NASA missions resilient to threats. The standard is normative authority for its NASA scope, not demonstration that a particular system satisfies the requirements or that a generation-ship architecture is integrated or assured.
  18. claim-source · src-cr-nist-controls-80053r5

    Security and Privacy Controls for Information Systems and Organizations (opens external site in a new tab)

    Record fingerprint
    efe4dc6860fbdda228dced85b87695df8d60684aeb6526e328be4724db7cc583
    Minimum approvals
    1
    Required scope groups
    bounded-competence: information-science
    High-consequence domains
    None under the named two-person rule
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    src-cr-nist-controls-80053r5
    Title
    Security and Privacy Controls for Information Systems and Organizations
    Authors
    1. Joint Task Force
    Publisher
    NIST
    Year
    2020
    Kind
    Government security privacy control catalog (exact value: government-security-privacy-control-catalog)
    Checked At
    2026-07-25
    Scope Note
    Control families spanning access, audit, contingency, identity, incident response, privacy, supply chain, communications, and system integrity; a catalog to tailor, not a certified architecture.
  19. claim-source · src-cr-nist-crypto-agility-cswp39u1

    Considerations for Achieving Crypto Agility: Strategies and Practices (opens external site in a new tab)

    Record fingerprint
    e00c46443bd97a74130ad2e19af942cfe9a635c7eea66e135de4171632673b05
    Minimum approvals
    1
    Required scope groups
    bounded-competence: information-science
    High-consequence domains
    None under the named two-person rule
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    src-cr-nist-crypto-agility-cswp39u1
    Title
    Considerations for Achieving Crypto Agility: Strategies and Practices
    Authors
    1. Elaine Barker
    2. Lily Chen
    3. David Cooper
    4. Dustin Moody
    5. Andrew Regenscheid
    6. Murugiah Souppaya
    7. William Newhouse
    8. Russ Housley
    9. Sean Turner
    10. William Barker
    11. Karen Kent
    Publisher
    NIST
    Year
    2026
    Kind
    Government cryptographic transition guidance (exact value: government-cryptographic-transition-guidance)
    Checked At
    2026-07-25
    Scope Note
    Inventory, discovery, operational mechanisms, transition strategies, protocol and application considerations, trade-offs, and open work for cryptographic agility; updated through 2026-06-29.
  20. claim-source · src-cr-nist-cyber-resilience-800160v2r1

    Developing Cyber-Resilient Systems: A Systems Security Engineering Approach (opens external site in a new tab)

    Record fingerprint
    44c9cb7acf30fe7dae9002044900433af81212da661b965f9264af72a409aec1
    Minimum approvals
    1
    Required scope groups
    bounded-competence: information-science
    High-consequence domains
    None under the named two-person rule
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    src-cr-nist-cyber-resilience-800160v2r1
    Title
    Developing Cyber-Resilient Systems: A Systems Security Engineering Approach
    Authors
    1. National Institute of Standards and Technology
    Publisher
    NIST
    Year
    2021
    Kind
    Government cyber resilience guidance (exact value: government-cyber-resilience-guidance)
    Checked At
    2026-07-25
    Scope Note
    Cyber-resiliency goals, objectives, techniques, approaches, design principles, and systems-engineering lifecycle; not a generation-ship architecture or certification.
  21. claim-source · src-cr-nist-fips203-mlkem

    Module-Lattice-Based Key-Encapsulation Mechanism Standard (opens external site in a new tab)

    Record fingerprint
    a8bc98ef3f8daf79edc2206df6273a4f8e046a98b172df40a11061d4b936f78a
    Minimum approvals
    1
    Required scope groups
    bounded-competence: information-science
    High-consequence domains
    None under the named two-person rule
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    src-cr-nist-fips203-mlkem
    Title
    Module-Lattice-Based Key-Encapsulation Mechanism Standard
    Authors
    1. National Institute of Standards and Technology
    Publisher
    NIST
    Year
    2024
    Kind
    Government cryptographic standard (exact value: government-cryptographic-standard)
    Checked At
    2026-07-25
    Scope Note
    ML-KEM algorithms and parameter sets for establishing shared secrets; NIST lists potential updates and does not claim century-scale security or implementation assurance.
  22. claim-source · src-cr-nist-fips204-mldsa

    Module-Lattice-Based Digital Signature Standard (opens external site in a new tab)

    Record fingerprint
    4b47fc94489002ab20d4e7858bcf1ddfce9f09ec939fa84ced8271cb124eba1e
    Minimum approvals
    1
    Required scope groups
    bounded-competence: information-science
    High-consequence domains
    None under the named two-person rule
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    src-cr-nist-fips204-mldsa
    Title
    Module-Lattice-Based Digital Signature Standard
    Authors
    1. National Institute of Standards and Technology
    Publisher
    NIST
    Year
    2024
    Kind
    Government cryptographic standard (exact value: government-cryptographic-standard)
    Checked At
    2026-07-25
    Scope Note
    ML-DSA digital-signature algorithms and parameter sets; standardization does not establish indefinite security, implementation correctness, or archival continuity.
  23. claim-source · src-cr-nist-firmware-800193

    Platform Firmware Resiliency Guidelines (opens external site in a new tab)

    Record fingerprint
    08984a00ed4540ac34b3290412d4c5c6eddd595f4207fee8aa92a63c48b9017c
    Minimum approvals
    1
    Required scope groups
    bounded-competence: information-science
    High-consequence domains
    None under the named two-person rule
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    src-cr-nist-firmware-800193
    Title
    Platform Firmware Resiliency Guidelines
    Authors
    1. Andrew Regenscheid
    Publisher
    NIST
    Year
    2018
    Kind
    Government platform resilience guidance (exact value: government-platform-resilience-guidance)
    Checked At
    2026-07-25
    Scope Note
    Roots of trust and mechanisms to protect, detect, and recover platform firmware and critical data after destructive attacks.
  24. claim-source · src-cr-nist-incident-80061r3

    Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile (opens external site in a new tab)

    Record fingerprint
    5f3dd381a84f21187a92324d4aa5da91ce04e14d59aef5f5faaca6227359d59d
    Minimum approvals
    1
    Required scope groups
    bounded-competence: information-science
    High-consequence domains
    None under the named two-person rule
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    src-cr-nist-incident-80061r3
    Title
    Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile
    Authors
    1. Alexander Nelson
    2. Sanjay Rekhi
    3. Murugiah Souppaya
    4. Karen Scarfone
    Publisher
    NIST
    Year
    2025
    Kind
    Government incident response guidance (exact value: government-incident-response-guidance)
    Checked At
    2026-07-25
    Scope Note
    Incident preparation, detection, response, recovery, communications, analysis, mitigation, and improvement across CSF 2.0 functions.
  25. claim-source · src-cr-nist-key-management-80057p1r5

    Recommendation for Key Management: Part 1 — General (opens external site in a new tab)

    Record fingerprint
    8de5e1eb786969d11a6a1544085a1663f7c54cfb69eb79f4de3da9231844c3cf
    Minimum approvals
    1
    Required scope groups
    bounded-competence: information-science
    High-consequence domains
    None under the named two-person rule
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    src-cr-nist-key-management-80057p1r5
    Title
    Recommendation for Key Management: Part 1 — General
    Authors
    1. Elaine Barker
    Publisher
    NIST
    Year
    2020
    Kind
    Government key management guidance (exact value: government-key-management-guidance)
    Checked At
    2026-07-25
    Scope Note
    Cryptographic services, key types, lifecycle functions, protection, compromise, backup, recovery, archival, and destruction.
  26. claim-source · src-cr-nist-recovery-800184

    Guide for Cybersecurity Event Recovery (opens external site in a new tab)

    Record fingerprint
    d43cc61a580591a7ef3ddd073f2913df1e480bf7d7866279bca0d53880fd780c
    Minimum approvals
    1
    Required scope groups
    bounded-competence: information-science
    High-consequence domains
    None under the named two-person rule
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    src-cr-nist-recovery-800184
    Title
    Guide for Cybersecurity Event Recovery
    Authors
    1. Michael Bartock
    2. Jeffrey Cichonski
    3. Murugiah Souppaya
    4. Matthew Smith
    5. Greg Witte
    6. Karen Scarfone
    Publisher
    NIST
    Year
    2016
    Kind
    Government cyber recovery guidance (exact value: government-cyber-recovery-guidance)
    Checked At
    2026-07-25
    Scope Note
    Recovery planning, playbooks, testing, metrics, restoration, and improvement for current organizations; assumes terrestrial institutional support.
  27. claim-source · src-cr-nist-scrm-800161r1u1

    Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations (opens external site in a new tab)

    Record fingerprint
    02be470198b0c48432a90e4c5ac8374c588bad818fe7b37a7b663719ccab90bf
    Minimum approvals
    1
    Required scope groups
    bounded-competence: information-science
    High-consequence domains
    None under the named two-person rule
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    src-cr-nist-scrm-800161r1u1
    Title
    Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations
    Authors
    1. Jon Boyens
    2. Angela Smith
    3. Nadya Bartol
    4. Kris Winkler
    5. Alex Holbrook
    6. Matthew Fallon
    Publisher
    NIST
    Year
    2024
    Kind
    Government supply chain risk guidance (exact value: government-supply-chain-risk-guidance)
    Checked At
    2026-07-25
    Scope Note
    Multilevel lifecycle guidance for identifying, assessing, and mitigating malicious functionality, counterfeit, tampering, and poor development or manufacturing practice.
  28. claim-source · src-cr-nist-ssdf-800218

    Secure Software Development Framework (SSDF) Version 1.1 (opens external site in a new tab)

    Record fingerprint
    bda553d2c9f6bc9091b819eb153491cf8392cac73836f86a15eefee22fac1003
    Minimum approvals
    1
    Required scope groups
    bounded-competence: information-science
    High-consequence domains
    None under the named two-person rule
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    src-cr-nist-ssdf-800218
    Title
    Secure Software Development Framework (SSDF) Version 1.1
    Authors
    1. Murugiah Souppaya
    2. Karen Scarfone
    3. Donna Dodson
    Publisher
    NIST
    Year
    2022
    Kind
    Government secure development guidance (exact value: government-secure-development-guidance)
    Checked At
    2026-07-25
    Scope Note
    Outcome-based practices for preparing an organization, protecting software, producing well-secured releases, and responding to vulnerabilities.
  29. claim-source · src-cr-nist-zero-trust-800207

    Zero Trust Architecture (opens external site in a new tab)

    Record fingerprint
    4084c1d50c6edb3efc017ff0bfe23d5280297df0258c440ca27973d10702e901
    Minimum approvals
    1
    Required scope groups
    bounded-competence: information-science
    High-consequence domains
    None under the named two-person rule
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    src-cr-nist-zero-trust-800207
    Title
    Zero Trust Architecture
    Authors
    1. Scott Rose
    2. Oliver Borchert
    3. Stu Mitchell
    4. Sean Connelly
    Publisher
    NIST
    Year
    2020
    Kind
    Government cybersecurity architecture guidance (exact value: government-cybersecurity-architecture-guidance)
    Checked At
    2026-07-25
    Scope Note
    Resource-focused zero-trust tenets, logical components, deployment models, and threats for enterprise systems; does not establish closed-habitat integration.
  30. claim-source · src-im-nasa-eee-873910

    Electrical, Electronic, and Electromechanical Parts Assurance Standard (opens external site in a new tab)

    Record fingerprint
    7de974366c68ddd53ce47a7829040b0f7d644de2713f873827f7eacbe97c2287
    Minimum approvals
    1
    Required scope groups
    bounded-competence: information-science
    High-consequence domains
    None under the named two-person rule
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    src-im-nasa-eee-873910
    Title
    Electrical, Electronic, and Electromechanical Parts Assurance Standard
    Authors
    1. National Aeronautics and Space Administration
    Publisher
    NASA
    Year
    2017
    Kind
    Active electronic parts assurance standard (exact value: active-electronic-parts-assurance-standard)
    Checked At
    2026-07-25
    Scope Note
    Selection, acquisition, traceability, testing, handling, packaging, storage, application, and risk control for spaceflight electronic and electromechanical parts.
  31. claim-source · src-im-nasa-metrology-873912

    Metrology and Calibration (opens external site in a new tab)

    Record fingerprint
    8fa80c312101f162e43d1a51a136596e2cd0ff81f1b218ff7227df062b3e3540
    Minimum approvals
    1
    Required scope groups
    bounded-competence: information-science
    High-consequence domains
    None under the named two-person rule
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    src-im-nasa-metrology-873912
    Title
    Metrology and Calibration
    Authors
    1. National Aeronautics and Space Administration
    Publisher
    NASA
    Year
    2024
    Kind
    Active metrology calibration standard (exact value: active-metrology-calibration-standard)
    Checked At
    2026-07-25
    Scope Note
    Selection, calibration, control, and use of measuring and test equipment whose results affect safety or mission success.
  32. claim-source · src-im-nasa-std-6030

    Additive Manufacturing Requirements for Spaceflight Systems (opens external site in a new tab)

    Record fingerprint
    7e6a5d45f27e760d46772f9f030ecd9397047f8274aa4525946c18e6d6b34d90
    Minimum approvals
    1
    Required scope groups
    bounded-competence: information-science
    High-consequence domains
    None under the named two-person rule
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    src-im-nasa-std-6030
    Title
    Additive Manufacturing Requirements for Spaceflight Systems
    Authors
    1. National Aeronautics and Space Administration
    Publisher
    NASA
    Year
    2021
    Kind
    Active spaceflight manufacturing standard (exact value: active-spaceflight-manufacturing-standard)
    Checked At
    2026-07-26
    Version
    Baseline
    Change Number
    0
    Document Date
    2021-04-21
    Status
    ACTIVE
    Review Due
    2026-04-21
    Freshness Note
    NASA still marks the baseline ACTIVE even though the listed five-year review date has passed; GShips therefore treats it as current-with-review-due rather than obsolete.
    Scope Note
    Requirements for part classification, feedstock and process control, machine qualification, witness material, inspection, acceptance, configuration, and tailored in-space additive manufacturing. This is normative authority for NASA spaceflight hardware, not a demonstration of printed-part performance, autonomous repair, circular manufacturing, or cyber recovery.
  33. claim-source · src-pn-ietf-bpsec

    RFC 9172: Bundle Protocol Security (opens external site in a new tab)

    Record fingerprint
    266d01cc374ffb39ae67ac92d5819b03617401cdf12935e25b0dea13f4a3a1d4
    Minimum approvals
    1
    Required scope groups
    bounded-competence: information-science
    High-consequence domains
    None under the named two-person rule
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    src-pn-ietf-bpsec
    Title
    RFC 9172: Bundle Protocol Security
    Authors
    1. Edward Birrane
    2. Kurt McKeever
    Publisher
    Internet Engineering Task Force
    Year
    2022
    Kind
    Internet standard (exact value: internet-standard)
    Checked At
    2026-07-25
    Scope Note
    Bundle integrity and confidentiality blocks, security processing, threat assumptions, key-management exclusions, and interoperability requirements.
  34. claim-source · src-pn-jpl-dsac

    Working Overtime: NASA's Deep Space Atomic Clock Completes Mission (opens external site in a new tab)

    Record fingerprint
    eb44d6f5e829543be29e410f9cc10f9588df681ae8fe28478bfb705f4c47c199
    Minimum approvals
    1
    Required scope groups
    bounded-competence: information-science
    High-consequence domains
    None under the named two-person rule
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    src-pn-jpl-dsac
    Title
    Working Overtime: NASA's Deep Space Atomic Clock Completes Mission
    Authors
    1. Jet Propulsion Laboratory
    Publisher
    NASA Jet Propulsion Laboratory
    Year
    2021
    Kind
    Technology demonstration record (exact value: technology-demonstration-record)
    Checked At
    2026-07-25
    Scope Note
    Deep Space Atomic Clock mission duration, spaceflight technology-demonstration boundary, and reported timing stability over more than twenty days.
Equivalent record table for this packet
RecordSubjectFingerprintApprovalsScope groups
system:cybersecurity Cybersecurity, software assurance & recovery 48a0199de1d45db9fdb9aad2b20fcd4d219be2d336a58c2b4b44921d27a82a21 1 bounded-competence: defensive-cyber-safety, security-assurance
claim:claim-12-01 Generation-ship security protects a civilization’s ability to operate, repair, govern, learn, and recover without an external rescuer—not merely its secrets. 908842da73f03771a9e09cc29bdc8e3863610f7ab9de665f452f153f7bb618b1 2 domain-method: defensive-cyber-safety, governance-law-rights, security-assurance; rights-public-interest: affected-public-rights
claim:claim-12-02 Space-sector guidance and protocol-security reports, operational-technology, software-supply-chain, zero-trust, post-quantum, and cyber-resilience standards provide relevant but fragmented reference points; their existence does not establish integration or assurance. 0f49699074aad1bdc4026a7e08cecd517f96beb614fa4055762c508de9fa31fc 2 domain-method: defensive-cyber-safety, dual-use-risk, security-assurance; rights-public-interest: affected-public-rights
claim:claim-12-03 Secure firmware-update patterns, platform recovery, software-component inventories, bundle-layer security for disrupted networking, and a publicly described CCSDS-oriented space-data-link cryptography library exist in different contexts. Availability does not establish compatibility, conformance, flight qualification, safe integration, or century maintenance. 6055efdd9314736b322ecafce96268e59c3ddc2c7874b92f43b11b7494689e92 2 domain-method: defensive-cyber-safety, dual-use-risk, security-assurance; rights-public-interest: affected-public-rights
claim:claim-12-04 Within the public sources sampled for this foundation draft, we did not identify a generation-ship cybersecurity standard or a demonstrated century-scale cryptographic deployment. 1f2f998d50f9608459ee4d3da4ac355a5bf83f8c7d328e5d931ade7d5e4ec478 2 domain-method: defensive-cyber-safety, security-assurance; rights-public-interest: affected-public-rights
claim:claim-12-05 Trust anchors, identity, secure time, revocation, incident command, threshold recovery, crypto-agile migration, anti-rollback, and archival signature interpretation must work locally after permanent loss of Earth. 2811cbe867ae12c3b3d54f9da45439d26535ec4349f41ae4a7cb36eb37ea26a1 2 domain-method: defensive-cyber-safety, governance-law-rights, security-assurance; rights-public-interest: affected-public-rights
claim:claim-12-06 Insiders, collusion, governance capture, compromised suppliers, corrupted hardware, malicious maintenance, radiation faults, operator error, and generational loss of expertise must be addressed without turning safety monitoring into surveillance or political control. e661cc2789a8cd078b10a5fa6f5f4bb267c1dcdcc4156a6fd1870fa857a41db2 2 domain-method: defensive-cyber-safety, governance-law-rights, security-assurance; rights-public-interest: affected-public-rights
claim:claim-12-07 Onboard manufacturing makes malicious designs, poisoned toolchains, compromised metrology, counterfeit replacement parts, and configuration drift cyber-physical threats. aa41b5d69f1e2cb946f156453cc5e43165f992ffba714ec0b1562413e4751e5c 2 domain-method: defensive-cyber-safety, security-assurance; rights-public-interest: affected-public-rights
claim:claim-12-08 Disconnected trust fabrics, update airlocks, recovery vaults, and cyber ranges benefit critical infrastructure and remote industry. cf9e9af24876befe4386e5d20c5bd3940c82a2f55d410ae762b76cc43357ca22 2 domain-method: defensive-cyber-safety, dual-use-risk, security-assurance; rights-public-interest: affected-public-rights
claim:claim-12-09 Crypto agility and toolchain escrow reduce obsolescence risk in medical, energy, transport, and public systems. 4c3588aab47e1175acc7a32a66fd16e23f01df3fd603f3d4005e2e5503935290 2 domain-method: defensive-cyber-safety, security-assurance; rights-public-interest: affected-public-rights
claim:claim-12-10 Mixed crews must repeatedly isolate a compromised zone, maintain life support, investigate locally, rebuild from known-good material, and rejoin safely. 718e87306ab83c20b2c477e928406ce5697e01b1a5b64ab9cde6d6fbcbe148be 2 domain-method: defensive-cyber-safety, dual-use-risk, governance-law-rights, security-assurance; rights-public-interest: affected-public-rights
claim-source:src-cr-ccsds-350-0-g-3 The Application of Security to CCSDS Protocols 44f5371a3c01028d94ba87eb2c3367b47b781a3fe2f7de8e0bb5c7486278d8fb 1 bounded-competence: information-science
claim-source:src-cr-cisa-sbom Software Bill of Materials d551139e9329c0f04e2480582f3dd9123e7d717b8bfedf5cb6141bc087053d16 1 bounded-competence: information-science
claim-source:src-cr-ietf-rfc9019-suit A Firmware Update Architecture for Internet of Things f89082ee842c244fde0169bd864fb0a0b2e4390d2b8bda120bbe1fcb414b62e7 1 bounded-competence: information-science
claim-source:src-cr-nasa-cryptolib-2023 The State of CryptoLib – The Open-Source Satellite Cryptography Library 841fcaee2944c6aef6a4e4b5275ddaaea99533977c6de713671c428d94b6998c 1 bounded-competence: information-science
claim-source:src-cr-nasa-space-security-bpg-revb Space Security: Best Practices Guide 49def0ff9598b6f4abebd7c72c8abe70acd2cba861d8cb9407389b95a0ef3d94 1 bounded-competence: information-science
claim-source:src-cr-nasa-std-1006a Space System Protection Standard 21bc08c8476b722c9011a875a0feeef60390048860f419d797f96be3a5cf998a 1 bounded-competence: information-science
claim-source:src-cr-nist-controls-80053r5 Security and Privacy Controls for Information Systems and Organizations efe4dc6860fbdda228dced85b87695df8d60684aeb6526e328be4724db7cc583 1 bounded-competence: information-science
claim-source:src-cr-nist-crypto-agility-cswp39u1 Considerations for Achieving Crypto Agility: Strategies and Practices e00c46443bd97a74130ad2e19af942cfe9a635c7eea66e135de4171632673b05 1 bounded-competence: information-science
claim-source:src-cr-nist-cyber-resilience-800160v2r1 Developing Cyber-Resilient Systems: A Systems Security Engineering Approach 44c9cb7acf30fe7dae9002044900433af81212da661b965f9264af72a409aec1 1 bounded-competence: information-science
claim-source:src-cr-nist-fips203-mlkem Module-Lattice-Based Key-Encapsulation Mechanism Standard a8bc98ef3f8daf79edc2206df6273a4f8e046a98b172df40a11061d4b936f78a 1 bounded-competence: information-science
claim-source:src-cr-nist-fips204-mldsa Module-Lattice-Based Digital Signature Standard 4b47fc94489002ab20d4e7858bcf1ddfce9f09ec939fa84ced8271cb124eba1e 1 bounded-competence: information-science
claim-source:src-cr-nist-firmware-800193 Platform Firmware Resiliency Guidelines 08984a00ed4540ac34b3290412d4c5c6eddd595f4207fee8aa92a63c48b9017c 1 bounded-competence: information-science
claim-source:src-cr-nist-incident-80061r3 Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile 5f3dd381a84f21187a92324d4aa5da91ce04e14d59aef5f5faaca6227359d59d 1 bounded-competence: information-science
claim-source:src-cr-nist-key-management-80057p1r5 Recommendation for Key Management: Part 1 — General 8de5e1eb786969d11a6a1544085a1663f7c54cfb69eb79f4de3da9231844c3cf 1 bounded-competence: information-science
claim-source:src-cr-nist-recovery-800184 Guide for Cybersecurity Event Recovery d43cc61a580591a7ef3ddd073f2913df1e480bf7d7866279bca0d53880fd780c 1 bounded-competence: information-science
claim-source:src-cr-nist-scrm-800161r1u1 Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations 02be470198b0c48432a90e4c5ac8374c588bad818fe7b37a7b663719ccab90bf 1 bounded-competence: information-science
claim-source:src-cr-nist-ssdf-800218 Secure Software Development Framework (SSDF) Version 1.1 bda553d2c9f6bc9091b819eb153491cf8392cac73836f86a15eefee22fac1003 1 bounded-competence: information-science
claim-source:src-cr-nist-zero-trust-800207 Zero Trust Architecture 4084c1d50c6edb3efc017ff0bfe23d5280297df0258c440ca27973d10702e901 1 bounded-competence: information-science
claim-source:src-im-nasa-eee-873910 Electrical, Electronic, and Electromechanical Parts Assurance Standard 7de974366c68ddd53ce47a7829040b0f7d644de2713f873827f7eacbe97c2287 1 bounded-competence: information-science
claim-source:src-im-nasa-metrology-873912 Metrology and Calibration 8fa80c312101f162e43d1a51a136596e2cd0ff81f1b218ff7227df062b3e3540 1 bounded-competence: information-science
claim-source:src-im-nasa-std-6030 Additive Manufacturing Requirements for Spaceflight Systems 7e6a5d45f27e760d46772f9f030ecd9397047f8274aa4525946c18e6d6b34d90 1 bounded-competence: information-science
claim-source:src-pn-ietf-bpsec RFC 9172: Bundle Protocol Security 266d01cc374ffb39ae67ac92d5819b03617401cdf12935e25b0dea13f4a3a1d4 1 bounded-competence: information-science
claim-source:src-pn-jpl-dsac Working Overtime: NASA's Deep Space Atomic Clock Completes Mission eb44d6f5e829543be29e410f9cc10f9588df681ae8fe28478bfb705f4c47c199 1 bounded-competence: information-science

Frozen source snapshots

Source inclusion does not determine the disposition. Reviewers must inspect the cited locator and relation, note inaccessible material, and identify stronger or conflicting evidence.

Sources, verification dates, scope notes, and exact fingerprints
Source IDSourceCheckedScope boundaryFingerprint
src-cr-ccsds-350-0-g-3 The Application of Security to CCSDS Protocols (opens external site in a new tab) 2026-07-26 Consensus informational report on security concepts, mechanisms, implementation options, and effects on CCSDS services, primarily for space-ground and ground-space links. The report explicitly is not a CCSDS Recommended Standard and excludes detailed security-analysis and risk-assessment methods. 44f5371a3c01028d94ba87eb2c3367b47b781a3fe2f7de8e0bb5c7486278d8fb
src-cr-cisa-sbom Software Bill of Materials (opens external site in a new tab) 2026-07-25 Official SBOM definition, ecosystem roles, use cases, community resources, and minimum-elements guidance; an SBOM is component evidence rather than proof of safety. d551139e9329c0f04e2480582f3dd9123e7d717b8bfedf5cb6141bc087053d16
src-cr-ietf-rfc9019-suit A Firmware Update Architecture for Internet of Things (opens external site in a new tab) 2026-07-25 Informational IETF architecture for authenticated firmware manifests, stakeholder separation, target matching, sequence control, dependencies, interruption tolerance, and recovery. f89082ee842c244fde0169bd864fb0a0b2e4390d2b8bda120bbe1fcb414b62e7
src-cr-nasa-cryptolib-2023 The State of CryptoLib – The Open-Source Satellite Cryptography Library (opens external site in a new tab) 2026-07-26 Professionally reviewed conference record distributed in 2023; NTRS marks the available record onlyAbstract=true. The abstract describes an actively developed open-source C library that aims to be CCSDS Space Data Link Security compliant and reports selected Telecommand, Telemetry, and Advanced Orbiting Systems encryption and decryption functions. It does not establish CCSDS conformance, secure implementation, operational deployment, flight qualification, key-management assurance, or long-duration maintenance. 841fcaee2944c6aef6a4e4b5275ddaaea99533977c6de713671c428d94b6998c
src-cr-nasa-space-security-bpg-revb Space Security: Best Practices Guide (opens external site in a new tab) 2026-07-26 Public NASA guidance translating selected NIST SP 800-53 controls into space-vehicle and ground-segment mission language. It is a risk-based starting point and expressly does not replace required plans or establish a certified architecture, flight qualification, or long-duration assurance. 49def0ff9598b6f4abebd7c72c8abe70acd2cba861d8cb9407389b95a0ef3d94
src-cr-nasa-std-1006a Space System Protection Standard (opens external site in a new tab) 2026-07-26 Active Agency-level protection requirements intended to make NASA missions resilient to threats. The standard is normative authority for its NASA scope, not demonstration that a particular system satisfies the requirements or that a generation-ship architecture is integrated or assured. 21bc08c8476b722c9011a875a0feeef60390048860f419d797f96be3a5cf998a
src-cr-nist-aml-100-2e2025 Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (opens external site in a new tab) 2026-07-25 Predictive- and generative-AI evasion, poisoning, privacy, and misuse taxonomy, lifecycle stages, attacker capabilities, mitigations, and limitations. 1573c29a25a7b8302f31f3a676e7e80866b6ff58e0c0718e60a38f52ecbd3e5a
src-cr-nist-controls-80053r5 Security and Privacy Controls for Information Systems and Organizations (opens external site in a new tab) 2026-07-25 Control families spanning access, audit, contingency, identity, incident response, privacy, supply chain, communications, and system integrity; a catalog to tailor, not a certified architecture. efe4dc6860fbdda228dced85b87695df8d60684aeb6526e328be4724db7cc583
src-cr-nist-crypto-agility-cswp39u1 Considerations for Achieving Crypto Agility: Strategies and Practices (opens external site in a new tab) 2026-07-25 Inventory, discovery, operational mechanisms, transition strategies, protocol and application considerations, trade-offs, and open work for cryptographic agility; updated through 2026-06-29. e00c46443bd97a74130ad2e19af942cfe9a635c7eea66e135de4171632673b05
src-cr-nist-cyber-resilience-800160v2r1 Developing Cyber-Resilient Systems: A Systems Security Engineering Approach (opens external site in a new tab) 2026-07-25 Cyber-resiliency goals, objectives, techniques, approaches, design principles, and systems-engineering lifecycle; not a generation-ship architecture or certification. 44c9cb7acf30fe7dae9002044900433af81212da661b965f9264af72a409aec1
src-cr-nist-fips203-mlkem Module-Lattice-Based Key-Encapsulation Mechanism Standard (opens external site in a new tab) 2026-07-25 ML-KEM algorithms and parameter sets for establishing shared secrets; NIST lists potential updates and does not claim century-scale security or implementation assurance. a8bc98ef3f8daf79edc2206df6273a4f8e046a98b172df40a11061d4b936f78a
src-cr-nist-fips204-mldsa Module-Lattice-Based Digital Signature Standard (opens external site in a new tab) 2026-07-25 ML-DSA digital-signature algorithms and parameter sets; standardization does not establish indefinite security, implementation correctness, or archival continuity. 4b47fc94489002ab20d4e7858bcf1ddfce9f09ec939fa84ced8271cb124eba1e
src-cr-nist-firmware-800193 Platform Firmware Resiliency Guidelines (opens external site in a new tab) 2026-07-25 Roots of trust and mechanisms to protect, detect, and recover platform firmware and critical data after destructive attacks. 08984a00ed4540ac34b3290412d4c5c6eddd595f4207fee8aa92a63c48b9017c
src-cr-nist-incident-80061r3 Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile (opens external site in a new tab) 2026-07-25 Incident preparation, detection, response, recovery, communications, analysis, mitigation, and improvement across CSF 2.0 functions. 5f3dd381a84f21187a92324d4aa5da91ce04e14d59aef5f5faaca6227359d59d
src-cr-nist-key-management-80057p1r5 Recommendation for Key Management: Part 1 — General (opens external site in a new tab) 2026-07-25 Cryptographic services, key types, lifecycle functions, protection, compromise, backup, recovery, archival, and destruction. 8de5e1eb786969d11a6a1544085a1663f7c54cfb69eb79f4de3da9231844c3cf
src-cr-nist-recovery-800184 Guide for Cybersecurity Event Recovery (opens external site in a new tab) 2026-07-25 Recovery planning, playbooks, testing, metrics, restoration, and improvement for current organizations; assumes terrestrial institutional support. d43cc61a580591a7ef3ddd073f2913df1e480bf7d7866279bca0d53880fd780c
src-cr-nist-scrm-800161r1u1 Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations (opens external site in a new tab) 2026-07-25 Multilevel lifecycle guidance for identifying, assessing, and mitigating malicious functionality, counterfeit, tampering, and poor development or manufacturing practice. 02be470198b0c48432a90e4c5ac8374c588bad818fe7b37a7b663719ccab90bf
src-cr-nist-ssdf-800218 Secure Software Development Framework (SSDF) Version 1.1 (opens external site in a new tab) 2026-07-25 Outcome-based practices for preparing an organization, protecting software, producing well-secured releases, and responding to vulnerabilities. bda553d2c9f6bc9091b819eb153491cf8392cac73836f86a15eefee22fac1003
src-cr-nist-zero-trust-800207 Zero Trust Architecture (opens external site in a new tab) 2026-07-25 Resource-focused zero-trust tenets, logical components, deployment models, and threats for enterprise systems; does not establish closed-habitat integration. 4084c1d50c6edb3efc017ff0bfe23d5280297df0258c440ca27973d10702e901
src-im-nasa-eee-873910 Electrical, Electronic, and Electromechanical Parts Assurance Standard (opens external site in a new tab) 2026-07-25 Selection, acquisition, traceability, testing, handling, packaging, storage, application, and risk control for spaceflight electronic and electromechanical parts. 7de974366c68ddd53ce47a7829040b0f7d644de2713f873827f7eacbe97c2287
src-im-nasa-metrology-873912 Metrology and Calibration (opens external site in a new tab) 2026-07-25 Selection, calibration, control, and use of measuring and test equipment whose results affect safety or mission success. 8fa80c312101f162e43d1a51a136596e2cd0ff81f1b218ff7227df062b3e3540
src-im-nasa-std-6030 Additive Manufacturing Requirements for Spaceflight Systems (opens external site in a new tab) 2026-07-26 Requirements for part classification, feedstock and process control, machine qualification, witness material, inspection, acceptance, configuration, and tailored in-space additive manufacturing. This is normative authority for NASA spaceflight hardware, not a demonstration of printed-part performance, autonomous repair, circular manufacturing, or cyber recovery. 7e6a5d45f27e760d46772f9f030ecd9397047f8274aa4525946c18e6d6b34d90
src-im-nist-ot-80082r3 Guide to Operational Technology Security (opens external site in a new tab) 2026-07-25 Operational-technology architectures, safety and availability constraints, threats, segmentation, supply-chain and maintenance risks, countermeasures, and recovery. 079024b69f4ab4aeaa8755b5bf62674b9f4cae4428d4ea97744c9cb78cdb593e
src-pn-ccsds-oais Reference Model for an Open Archival Information System (opens external site in a new tab) 2026-07-25 OAIS information packages, representation information, designated communities, preservation planning, access, and archive-management functions. d130fb645b4838a8e446a7a861ad942052dcb493afd6bd7c431bd9e863999212
src-pn-ietf-bpsec RFC 9172: Bundle Protocol Security (opens external site in a new tab) 2026-07-25 Bundle integrity and confidentiality blocks, security processing, threat assumptions, key-management exclusions, and interoperability requirements. 266d01cc374ffb39ae67ac92d5819b03617401cdf12935e25b0dea13f4a3a1d4
src-pn-jpl-dsac Working Overtime: NASA's Deep Space Atomic Clock Completes Mission (opens external site in a new tab) 2026-07-25 Deep Space Atomic Clock mission duration, spaceflight technology-demonstration boundary, and reported timing stability over more than twenty days. eb44d6f5e829543be29e410f9cc10f9588df681ae8fe28478bfb705f4c47c199
official-claim-source-src-cr-ccsds-350-0-g-3 The Application of Security to CCSDS Protocols (opens external site in a new tab) Not recorded Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion. a86142f5fce60a71a0905f1944ad99c11fe7ff14098e81b6e06b38ce2b062243
official-claim-source-src-cr-cisa-sbom Software Bill of Materials (opens external site in a new tab) Not recorded Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion. 8ad5bd5d18cf9ba0ed05394d071fc0d59a42185d10b71351f3e02915cfd71353
official-claim-source-src-cr-ietf-rfc9019-suit A Firmware Update Architecture for Internet of Things (opens external site in a new tab) Not recorded Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion. 5004da9fb26005706036c9045418cb25c8751ef109f7f10e4e5a1e5eff6b6e7c
official-claim-source-src-cr-nasa-cryptolib-2023 The State of CryptoLib – The Open-Source Satellite Cryptography Library (opens external site in a new tab) Not recorded Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion. 40ad412fbfaa0c648ca88b0987a6ccae59ddde9351182e318cdeceba790a60c1
official-claim-source-src-cr-nasa-space-security-bpg-revb Space Security: Best Practices Guide (opens external site in a new tab) Not recorded Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion. f7c2741801ba160965ab6da62bbe88bdd2339c60415087810b8b092704e93807
official-claim-source-src-cr-nasa-std-1006a Space System Protection Standard (opens external site in a new tab) Not recorded Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion. b48c8e7e91dc3ed0a8fa8c23659173cb3b693ebc76d411162fc308ff83d5aafb
official-claim-source-src-cr-nist-controls-80053r5 Security and Privacy Controls for Information Systems and Organizations (opens external site in a new tab) Not recorded Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion. 9a3ada8c5c146d905b29cc1e413e2fa905c3836da2b7836d128db5b39125dba4
official-claim-source-src-cr-nist-crypto-agility-cswp39u1 Considerations for Achieving Crypto Agility: Strategies and Practices (opens external site in a new tab) Not recorded Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion. a63db25c84019efdd97e74dad0b0a1905cf61e8e74de79c6d7366073f7a544b2
official-claim-source-src-cr-nist-cyber-resilience-800160v2r1 Developing Cyber-Resilient Systems: A Systems Security Engineering Approach (opens external site in a new tab) Not recorded Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion. 8b735effbc75fac1763663ee0d90bf9aea61257c4bcc079db6b07b8f41015a75
official-claim-source-src-cr-nist-fips203-mlkem Module-Lattice-Based Key-Encapsulation Mechanism Standard (opens external site in a new tab) Not recorded Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion. d0c7e3c4b6eedbde48c92d0a27014c40ae500772630d2854545744daaeb3c98e
official-claim-source-src-cr-nist-fips204-mldsa Module-Lattice-Based Digital Signature Standard (opens external site in a new tab) Not recorded Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion. b9f67336a615ca438bf41855ce881364e2746e878f3571765643a2b058e7b879
official-claim-source-src-cr-nist-firmware-800193 Platform Firmware Resiliency Guidelines (opens external site in a new tab) Not recorded Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion. bef51fdba213dfb34855dc5bbaa9801705c0137feaca9eeaf3e21f6fdefa2407
official-claim-source-src-cr-nist-incident-80061r3 Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile (opens external site in a new tab) Not recorded Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion. b86d4235338d36cf38a3593ae6768af5dc6070c731fcdf52be345c707923829c
official-claim-source-src-cr-nist-key-management-80057p1r5 Recommendation for Key Management: Part 1 — General (opens external site in a new tab) Not recorded Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion. cff634fac3513561b69efe8d1c870f1818939af42248106bec73129462052dc6
official-claim-source-src-cr-nist-recovery-800184 Guide for Cybersecurity Event Recovery (opens external site in a new tab) Not recorded Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion. 45adc85e81855a49a86b1700fdd41a8794ce28c0fbf5fdc186edba75ca2dc013
official-claim-source-src-cr-nist-scrm-800161r1u1 Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations (opens external site in a new tab) Not recorded Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion. bc70656502f08d82397647a85e0e0a658e799b28722fca1fdba11120cf4b33df
official-claim-source-src-cr-nist-ssdf-800218 Secure Software Development Framework (SSDF) Version 1.1 (opens external site in a new tab) Not recorded Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion. 5cd722de28cc7500880aa153ae557902fae2b3fa095a2f83ab137b1cd6d85351
official-claim-source-src-cr-nist-zero-trust-800207 Zero Trust Architecture (opens external site in a new tab) Not recorded Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion. d6b902fc8f0575a2a7be4bdabb8767b991221c60e2784b36d83a2e44874f240f
official-claim-source-src-im-nasa-eee-873910 Electrical, Electronic, and Electromechanical Parts Assurance Standard (opens external site in a new tab) Not recorded Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion. 0cd9a24fa7e15e7cc62119e838b11483a4ab2a218f99543a8a20d460f9c60ffa
official-claim-source-src-im-nasa-metrology-873912 Metrology and Calibration (opens external site in a new tab) Not recorded Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion. a3b50382dd9f41e9f105d2d0d3867d5afeafcdb8a68b80d98c0975872692fc48
official-claim-source-src-im-nasa-std-6030 Additive Manufacturing Requirements for Spaceflight Systems (opens external site in a new tab) Not recorded Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion. 679a41ecc1d685fa0339014c60828d3a73add65d26f63eebd30e8260fe67db94
official-claim-source-src-pn-ietf-bpsec RFC 9172: Bundle Protocol Security (opens external site in a new tab) Not recorded Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion. 8ce6689f23672e15b4cb826b9846e914b0787b371328b8ff02fa68600ece1ab9
official-claim-source-src-pn-jpl-dsac Working Overtime: NASA's Deep Space Atomic Clock Completes Mission (opens external site in a new tab) Not recorded Official subject link frozen with the reviewed record; it does not independently validate every profile conclusion. a2301c5d95dfe6321a96bddb31d69c3abc5c9f5dd6880287d858fe97b6383a03

Offline packet and worksheet

Downloads contain no reviewer contact details. Downloading does not create an account or store a review response in the GShips application. Ordinary provider request or analytics logs may record the download request. Work locally: the public site has no review account, upload endpoint, or decision-submission API.

Frozen packet · JSON

137.7 KB · packet identity c143c856d4978f82…

Download packet

Blank decision worksheet · JSON

23.3 KB · template identity c990173cc0980b54…

Download blank JSON

Review-notes worksheet · Markdown

Readable notes companion only—not a decision-bundle equivalent. Use the closed JSON template for structural validation.

Download notes worksheet

Do not paste a completed decision, identity documents, private contact data, confidential conflict evidence, medical information, controlled material, or exploit details into a public form. Until a separately authorized private handoff exists, retain the completed worksheet locally.

Packet schema · JSON · Decision-bundle schema · JSON

Validate offline

Use Node.js 22.13.0 or later. Keep the packet, worksheet, completed decision, and all six kit files together in a local directory.

  1. Download the six kit files below. Complete a copy of the JSON template offline and preserve its templateFingerprint.
  2. Finalize a separate output file.
    node finalize-review-decision.mjs \
      --input DRAFT.json \
      --output COMPLETED.json

    This marks the copy complete and calculates an unkeyed canonical bundle fingerprint. A fingerprint detects changes; it is not a reviewer signature.

  3. Validate the packet and completed copy.
    node check-review-decisions.mjs \
      --packet PACKET.json \
      --decision COMPLETED.json

    Add another --decision for each independent reviewer.

  4. Interpret the result narrowly. A zero exit proves structural consistency only. Neither command appoints or qualifies a reviewer, establishes independence, accepts a decision, or authorizes publication.

Completion criteria

Every primary record must receive the required number of valid, current-fingerprint approvals; every complementary scope group and required domain must be covered; any unresolved revise, contest, or reject disposition blocks publication.

Named medical, reproductive, nuclear, radiation, cybersecurity, governance, and dual-use conclusions require two distinct qualified independent humans covering complementary domain-method and rights/public-interest scopes.

  • Reviewer identity, qualification, independence, conflicts, and compensation must be assessed by accountable human governance; local validation can only report structural validity.
  • Approve, revise, contest, reject, and recuse remain visible. A negative finding cannot be hidden by an aggregate approval percentage.
  • Revision creates a new record and packet fingerprint. Prior approvals do not carry forward automatically.
  • AI may assist with clerical comparison but cannot count as an independent reviewer, identity attestor, appeal authority, or second person.

Prepared review packet · 0 published human decisions · Independent review pending · Suggest a correction

Accountability record

How to inspect this page

Scope: Prepared review packet systems:cybersecurity · c143c856d4978f824701c6831dcc968482b4215f700f53579ca3d4d6155f9b0d

Page citations and accountability links

  • Exact frozen packet
    Complete packet payload; SHA-256 c143c856d4978f824701c6831dcc968482b4215f700f53579ca3d4d6155f9b0d · fingerprint-bound review artifact
  • Blank closed decision template
    Offline structured-decision starting point · unsubmitted local artifact
  • Review-notes worksheet
    Human-readable notes companion; not validator input · offline notes aid
  • Review corpus index
    Corpus SHA-256 8fa944604ca189f5a9216ca59f640ad2ca20972ad512f2f4970764716782e18d · release and ownership index

Assumptions and limits

  • The exact packet, record, source, policy, release, and source-commit fingerprints bound this prepared page; human review has not started.
  • Downloading, local structural validation, or completing notes does not appoint or qualify a reviewer, establish independence, accept a decision, authorize publication, or create a relationship.

What would change this page?

Staffed governance, appointed qualified reviewers, completed record-level decisions, published conflicts, minority findings, corrections, or changed review policy would change this page.

People, review, and conflicts

Prepared by
GShips Project
Editorial status
public-alpha accountability pass
Editorial reviewer
GShips Project AI-assisted editorial synthesis
Last editorial review
2026-07-26
Independent review
pending
Independent reviewer
No independent reviewer assigned
Last independent review
No independent-review date exists
Last content edit
2026-07-25

Declared conflicts

  • The maintainer intends to explore a commercial venture based on some GShips work. No entity, outside funding, customer, sponsor, or indexed-organization relationship currently exists.

Suggest a correction to this page