{"id":3404,"date":"2024-05-03T14:54:43","date_gmt":"2024-05-03T19:54:43","guid":{"rendered":"https:\/\/www.darkreading.com\/ics-ot-security\/gao-nasa-faces-inconsistent-cybersecurity-across-spacecraft"},"modified":"2024-05-03T14:54:43","modified_gmt":"2024-05-03T19:54:43","slug":"gao-nasa-faces-inconsistent-cybersecurity-across-spacecraft","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/03\/gao-nasa-faces-inconsistent-cybersecurity-across-spacecraft\/","title":{"rendered":"GAO: NASA Faces &#8216;Inconsistent&#8217; Cybersecurity Across Spacecraft"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt16f112a988be320f\/66353f40bf9995b1ad645b13\/space-dotted_zebra-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/gao-nasa-faces-inconsistent-cybersecurity-across-spacecraft.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/gao-nasa-faces-inconsistent-cybersecurity-across-spacecraft.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">NASA has gone some way to addressing <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/risk\/nasa-breaches-leak-iss-control-code\" rel=\"noopener\">its cybersecurity challenges<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, according to a government watchdog, but, it says, too many of its security policies and standards are still optional.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The US Government Accountability Office (GAO) recently completed a review of three NASA projects: the Gateway Power and Propulsion Element, the Orion Multi-Purpose Crew Vehicle, and the Spectro-Photometer for the History of the Universe, Epoch of Reionization and Ices Explorer (SPHEREx). GAO found that contracts relating to these projects required contractors to address cybersecurity by, for example, adequately addressing and testing positioning, navigation, and timing systems.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">However, since issuing its <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/discovery.larc.nasa.gov\/PDF_FILES\/2019AO\/nasa-std-1006.pdf\" rel=\"noopener\">Space System Protection Standard<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in 2019, NASA hasn&#8217;t updated its policies and standards pertaining to those contracts. Plus, NASA issued a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/swehb.nasa.gov\/display\/SWEHBVD\/7.22+-+Space+Security%3A+Best+Practices+Guide\" rel=\"noopener\">Space Security: Best Practices Guide<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> last December, but the guidance is optional for spacecraft programs.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In concluding its report, GAO recommended that NASA &#8220;develop a plan with time frames&#8221; to update its policies.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Solving security at NASA is &#8220;not going to happen overnight,&#8221;&nbsp; notes Kevin Kirkwood, deputy CISO at LogRhythm. &#8220;It&#8217;s going to be an interesting and long journey: first to get the foundation in place from a policy perspective, and then the technology has to follow that through. And if they don&#8217;t figure out a way to make it work, they&#8217;re going to be in worse trouble than they are today.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Security vs. Practicality\">Security vs. Practicality<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In his response to the report, NASA CIO Jeffrey Seaton agreed with &#8220;the need to ensure continuous improvement of policies and standards,&#8221; but pushed back on GAO&#8217;s final recommendation. Among his reasons, Seaton pointed out two inescapable realities of cybersecurity in space.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">First, spacecraft are very diverse; NASA launches small satellites and manned aircraft, and &#8220;therefore, it is not feasible to develop one set of essential controls applicable to all types of mission spacecraft,&#8221; Seaton wrote.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Second, spacecraft machinery is unlike the computers used on Earth. The engineering constraints involved make safely implementing cutting-edge cybersecurity capabilities &#8220;non trivial.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;It comes down to space, weight, and power,&#8221; explains Jeff Hall, principal security consultant and North American aerospace lead at NCC Group. &#8220;Adding things takes away from your space, weight, and power budget, which is critical, because you&#8217;re already very constrained.&#8221; This is especially problematic if a spacecraft is already built \u2014 with that budget already accounted for \u2014 and one tries tacking on security after the fact.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;I&#8217;ve dealt with this firsthand on the engineering side, with aircraft and missiles and weapons systems for DoD,&#8221; Hall adds. A lot of the people that are on the IT side of things \u2014 you know, CIOs, CISOs \u2014 don&#8217;t have operational technology experience and they try to come at you with traditional IT solutions. Operational technology is very memory-limited. It&#8217;s very processor limited. It&#8217;s designed to do specific functions and nothing else. So hosting additional software \u2014 endpoint detection, anything like that \u2014 just does not work for a system like this.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Finding the right balance between engineering constraints and security robustness is necessary, Kirkwood warns, in the face of those <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-analytics\/how-researchers-hijacked-a-satellite\" rel=\"noopener\">worst-case scenario, science-fiction-level threats<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to NASA&#8217;s most valuable systems.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;If you can inject yourself anywhere in the [spacecraft&#8217;s] pipeline, you can begin to do funny things like send a signal that changes the way it&#8217;s navigating,&#8221; he says. &#8220;Or you can heat things up that need to be cold, like food. You could send a signal up to the space station to tell the whole environment to shut off. Deep space is pretty cold \u2014 the astronauts are going to notice that they&#8217;re a little chilly and they&#8217;re going to need to do something about it.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;It&#8217;s things like that that should be thought through and architecturally fixed before you actually ever put somebody up in a spacecraft.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/gao-nasa-faces-inconsistent-cybersecurity-across-spacecraft\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>NASA has gone some way to addressing its cybersecurity challenges,<\/p>\n","protected":false},"author":12,"featured_media":3405,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3404","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/gao-nasa-faces-inconsistent-cybersecurity-across-spacecraft-scaled.jpg?fit=2560%2C1440&ssl=1",2560,1440,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/gao-nasa-faces-inconsistent-cybersecurity-across-spacecraft-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/gao-nasa-faces-inconsistent-cybersecurity-across-spacecraft-scaled.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/gao-nasa-faces-inconsistent-cybersecurity-across-spacecraft-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/gao-nasa-faces-inconsistent-cybersecurity-across-spacecraft-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/gao-nasa-faces-inconsistent-cybersecurity-across-spacecraft-scaled.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/gao-nasa-faces-inconsistent-cybersecurity-across-spacecraft-scaled.jpg?fit=2048%2C1152&ssl=1",2048,1152,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/gao-nasa-faces-inconsistent-cybersecurity-across-spacecraft-scaled.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/gao-nasa-faces-inconsistent-cybersecurity-across-spacecraft-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/gao-nasa-faces-inconsistent-cybersecurity-across-spacecraft-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/gao-nasa-faces-inconsistent-cybersecurity-across-spacecraft-scaled.jpg?fit=2560%2C1440&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3404","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3404"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3404\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3405"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3404"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3404"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3404"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}