The civil space cybersecurity requirements that Interior, Commerce and NASA recommend for FAR contract language take a risk-based, tiered approach for all new civil space systems, apply at least to on-orbit and link segments, and for the highest-risk tier protect command and control, including backup or failover systems, by encrypting commands for confidentiality, ensuring commands are not modified in transit, ensuring an authorized party is the source of commands, and rejecting unauthorized command and control attempts.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.