15% of Space ISAC (Information Sharing and Analysis Center) you already have
ASD Strategies to Mitigate Cyber Security Incidents already covers about 15% of Space ISAC (Information Sharing and Analysis Center), leaving
34 of 40 controls as genuinely new work.
Already covered 1
Likely covered 5
New work 34
What is genuinely new work
Nothing in ASD Strategies to Mitigate Cyber Security Incidents reaches these. This is the list to scope.
CT-4Uplink and Downlink Manipulation
GC-1Norms of Responsible Behavior
GC-2Public-Private Information Sharing
GC-3Cross-Sector Coordination
GC-4Technology-Agnostic Threat Formats
GT-1Ground Station Cyber Attacks
SISAC-01Membership and Trusted Community Onboarding
SISAC-02Space Asset Inventory and Classification
SISAC-03Adversary TTP Mapping for Space Systems
SISAC-04Indicator and Threat Intelligence Sharing
SISAC-05Command and Telemetry Link Protection
SISAC-06Ground Segment Hardening
SISAC-07Supply Chain Risk Management for Space Hardware
SISAC-08Flight Software Assurance
SISAC-09On-Orbit Anomaly Detection
SISAC-10GNSS and Position, Navigation and Timing Resilience
SISAC-11Space System Incident Response
SISAC-12Threat Information Production and Quality
SISAC-13Insider Threat Programme
SISAC-14Vulnerability Management for Space Systems
SISAC-15Tabletop and Red Team Exercises
SISAC-16Cross Sector and Critical Infrastructure Coordination
SISAC-17Encryption Key Lifecycle for Space Systems
SISAC-18User Terminal and Edge Device Security
SISAC-19Launch Phase Cybersecurity
SISAC-20Metrics, Maturity and Continuous Improvement
ST-1Satellite Cyber Intrusion
ST-2On-Orbit Interference
ST-3Anti-Satellite Weapons
ST-4Space Debris as Threat
TI-1STIX Framework for Space
TI-2TAXII Transport Protocol
TI-3Indicator of Compromise Sharing
TI-4Threat Correlation and Analysis
Show the 6 you already have
GT-4Social Engineering Attacks
CT-1RF Interference and Jamming
GT-2Physical Security Threats
GT-3Supply Chain Compromise
How this is calculated
Already covered means a mapping runs from a control in ASD Strategies to Mitigate Cyber Security Incidents to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition