Back to Frameworks

Space ISAC (Information Sharing and Analysis Center) - Threat Framework

International (Space Industry)
v2024 (ongoing)
24 domains
40 controls

The Space Information Sharing and Analysis Center (Space ISAC), launched in 2019 and operational from 2020, provides threat intelligence, vulnerability coordination, and incident response support for the global space industry. Housed at the National Cybersecurity Center in Colorado Springs. Members include satellite operators, launch providers, ground system operators, and space-related government agencies. The Space ISAC threat framework categorises space-specific cyber and physical threats, provides indicators of compromise (IOCs), and coordinates vulnerability disclosure for space systems. Key focus areas include: ground segment cyber threats, space segment RF/cyber attacks, supply chain integrity, and space weather impacts.

Unverified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (24)

Asset Management

1 controls
Controls in the Asset Management domain of Space ISAC (Information Sharing and Analysis Center) - Threat Framework1 controls
CodeTitle
SISAC-02Space Asset Inventory and Classification

Communications Link Threats

4 controls
Controls in the Communications Link Threats domain of Space ISAC (Information Sharing and Analysis Center) - Threat Framework4 controls
CodeTitle
CT-1RF Interference and Jamming
CT-2GNSS Spoofing
CT-3Signal Interception
CT-4Uplink and Downlink Manipulation

Communications Security

1 controls
Controls in the Communications Security domain of Space ISAC (Information Sharing and Analysis Center) - Threat Framework1 controls
CodeTitle
SISAC-05Command and Telemetry Link Protection

Coordination

1 controls
Controls in the Coordination domain of Space ISAC (Information Sharing and Analysis Center) - Threat Framework1 controls
CodeTitle
SISAC-16Cross Sector and Critical Infrastructure Coordination

Cryptography

1 controls
Controls in the Cryptography domain of Space ISAC (Information Sharing and Analysis Center) - Threat Framework1 controls
CodeTitle
SISAC-17Encryption Key Lifecycle for Space Systems

Detection

1 controls
Controls in the Detection domain of Space ISAC (Information Sharing and Analysis Center) - Threat Framework1 controls
CodeTitle
SISAC-09On-Orbit Anomaly Detection

Endpoint Security

1 controls
Controls in the Endpoint Security domain of Space ISAC (Information Sharing and Analysis Center) - Threat Framework1 controls
CodeTitle
SISAC-18User Terminal and Edge Device Security

Exercises

1 controls
Controls in the Exercises domain of Space ISAC (Information Sharing and Analysis Center) - Threat Framework1 controls
CodeTitle
SISAC-15Tabletop and Red Team Exercises

Governance

1 controls
Controls in the Governance domain of Space ISAC (Information Sharing and Analysis Center) - Threat Framework1 controls
CodeTitle
SISAC-01Membership and Trusted Community Onboarding

Governance and Collective Security

4 controls
Controls in the Governance and Collective Security domain of Space ISAC (Information Sharing and Analysis Center) - Threat Framework4 controls
CodeTitle
GC-1Norms of Responsible Behavior
GC-2Public-Private Information Sharing
GC-3Cross-Sector Coordination
GC-4Technology-Agnostic Threat Formats

Ground Segment Threats

4 controls
Controls in the Ground Segment Threats domain of Space ISAC (Information Sharing and Analysis Center) - Threat Framework4 controls
CodeTitle
GT-1Ground Station Cyber Attacks
GT-2Physical Security Threats
GT-3Supply Chain Compromise
GT-4Social Engineering Attacks

Incident Response

1 controls
Controls in the Incident Response domain of Space ISAC (Information Sharing and Analysis Center) - Threat Framework1 controls
CodeTitle
SISAC-11Space System Incident Response

Information Sharing

2 controls
Controls in the Information Sharing domain of Space ISAC (Information Sharing and Analysis Center) - Threat Framework2 controls
CodeTitle
SISAC-04Indicator and Threat Intelligence Sharing
SISAC-12Threat Information Production and Quality

Infrastructure Security

1 controls
Controls in the Infrastructure Security domain of Space ISAC (Information Sharing and Analysis Center) - Threat Framework1 controls
CodeTitle
SISAC-06Ground Segment Hardening

Operations

1 controls
Controls in the Operations domain of Space ISAC (Information Sharing and Analysis Center) - Threat Framework1 controls
CodeTitle
SISAC-19Launch Phase Cybersecurity

Personnel Security

1 controls
Controls in the Personnel Security domain of Space ISAC (Information Sharing and Analysis Center) - Threat Framework1 controls
CodeTitle
SISAC-13Insider Threat Programme

Programme Management

1 controls
Controls in the Programme Management domain of Space ISAC (Information Sharing and Analysis Center) - Threat Framework1 controls
CodeTitle
SISAC-20Metrics, Maturity and Continuous Improvement

Resilience

1 controls
Controls in the Resilience domain of Space ISAC (Information Sharing and Analysis Center) - Threat Framework1 controls
CodeTitle
SISAC-10GNSS and Position, Navigation and Timing Resilience

Software Security

1 controls
Controls in the Software Security domain of Space ISAC (Information Sharing and Analysis Center) - Threat Framework1 controls
CodeTitle
SISAC-08Flight Software Assurance

Space Segment Threats

4 controls
Controls in the Space Segment Threats domain of Space ISAC (Information Sharing and Analysis Center) - Threat Framework4 controls
CodeTitle
ST-1Satellite Cyber Intrusion
ST-2On-Orbit Interference
ST-3Anti-Satellite Weapons
ST-4Space Debris as Threat

Supply Chain

1 controls
Controls in the Supply Chain domain of Space ISAC (Information Sharing and Analysis Center) - Threat Framework1 controls
CodeTitle
SISAC-07Supply Chain Risk Management for Space Hardware

Threat Intelligence

1 controls
Controls in the Threat Intelligence domain of Space ISAC (Information Sharing and Analysis Center) - Threat Framework1 controls
CodeTitle
SISAC-03Adversary TTP Mapping for Space Systems

Threat Intelligence Sharing

4 controls
Controls in the Threat Intelligence Sharing domain of Space ISAC (Information Sharing and Analysis Center) - Threat Framework4 controls
CodeTitle
TI-1STIX Framework for Space
TI-2TAXII Transport Protocol
TI-3Indicator of Compromise Sharing
TI-4Threat Correlation and Analysis

Vulnerability Management

1 controls
Controls in the Vulnerability Management domain of Space ISAC (Information Sharing and Analysis Center) - Threat Framework1 controls
CodeTitle
SISAC-14Vulnerability Management for Space Systems

Your Compliance Coverage

If you comply with Space ISAC (Information Sharing and Analysis Center) - Threat Framework, you already cover:

Maps to 84 other frameworks

40 total controls
ISO/IEC 27011:2024
4 source controls mapped|5 target controls covered
10%
NIST Cybersecurity Framework 2.0
3 source controls mapped|6 target controls covered
8%
OWASP DevSecOps Maturity Model (DSOMM)
3 source controls mapped|1 target controls covered
8%
ITU Radio Regulations and Space Security Standards
3 source controls mapped|2 target controls covered
8%
UK Gambling Commission - Cyber Resilience Requirements
3 source controls mapped|1 target controls covered
8%
8%
NIST Privacy Framework
3 source controls mapped|3 target controls covered
8%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
3 source controls mapped|5 target controls covered
8%
FBI CJIS Security Policy
3 source controls mapped|3 target controls covered
8%
ISO 28001:2007 Supply Chain Security Management
3 source controls mapped|4 target controls covered
8%
FFIEC Cybersecurity Assessment Tool (CAT)
2 source controls mapped|4 target controls covered
5%
ISO/IEC 27400:2022
2 source controls mapped|2 target controls covered
5%
TISAX - Trusted Information Security Assessment Exchange
2 source controls mapped|2 target controls covered
5%
ISO/IEC 27010:2015
2 source controls mapped|2 target controls covered
5%
NIST SP 800-53 Rev 5
2 source controls mapped|6 target controls covered
5%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
2 source controls mapped|4 target controls covered
5%
BSI IT-Grundschutz
1 source controls mapped|1 target controls covered
3%
NIS2 Directive Implementing Acts
1 source controls mapped|1 target controls covered
3%
NAIC Insurance Data Security Model Law (MDL-668)
1 source controls mapped|1 target controls covered
3%
21 CFR Part 58 - Good Laboratory Practice (GLP)
1 source controls mapped|1 target controls covered
3%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
1 source controls mapped|1 target controls covered
3%
SOC 2
1 source controls mapped|1 target controls covered
3%
SSAE 18 - Attestation Standards (SOC Reporting)
1 source controls mapped|1 target controls covered
3%
Authorised Economic Operator (AEO) Programmes - Global Standards
1 source controls mapped|3 target controls covered
3%
UK FCA/PRA Operational Resilience Framework
1 source controls mapped|1 target controls covered
3%
SA8000:2014 - Social Accountability Standard
1 source controls mapped|1 target controls covered
3%
SASB Standards
1 source controls mapped|1 target controls covered
3%
PIC/S Guide to Good Manufacturing Practice for Medicinal Products
1 source controls mapped|1 target controls covered
3%
OWASP Top 10 for LLM Applications 2025
1 source controls mapped|1 target controls covered
3%
NIS2 Directive
1 source controls mapped|3 target controls covered
3%
NERC CIP
1 source controls mapped|1 target controls covered
3%
Modern Slavery Act 2018 (Australia)
1 source controls mapped|2 target controls covered
3%
IRM Enterprise Risk Management Framework (Institute of Risk Management)
1 source controls mapped|1 target controls covered
3%
IEEE 1686
1 source controls mapped|3 target controls covered
3%
ICH Q10 - Pharmaceutical Quality System
1 source controls mapped|1 target controls covered
3%
ICAO Annex 17 - Aviation Security (AVSEC)
1 source controls mapped|1 target controls covered
3%
IATF 16949:2016 - Quality Management System for Automotive Production
1 source controls mapped|1 target controls covered
3%
German Supply Chain Due Diligence Act (LkSG)
1 source controls mapped|2 target controls covered
3%
French Sapin II Law (Law No. 2016-1691)
1 source controls mapped|1 target controls covered
3%
FDA Quality Management System Regulation (QMSR)
1 source controls mapped|1 target controls covered
3%
API 1164
1 source controls mapped|3 target controls covered
3%
3%
APRA CPS 230 Operational Risk Management
1 source controls mapped|2 target controls covered
3%
BRCGS Global Standard for Food Safety Issue 9
1 source controls mapped|1 target controls covered
3%
Automotive SPICE (ASPICE) v4.0 - Process Assessment Model
1 source controls mapped|1 target controls covered
3%
AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
1 source controls mapped|2 target controls covered
3%
AS9100D - Aerospace Quality Management System
1 source controls mapped|3 target controls covered
3%
ISO/IEC 27003:2017
1 source controls mapped|3 target controls covered
3%
Annex 11 to EU GMP - Computerised Systems
1 source controls mapped|1 target controls covered
3%
21 CFR Part 211 - Current Good Manufacturing Practice
1 source controls mapped|1 target controls covered
3%
ISO/IEC 23894:2023
1 source controls mapped|1 target controls covered
3%
IEC 62443
1 source controls mapped|3 target controls covered
3%
BREEAM - Building Research Establishment Environmental Assessment Method
1 source controls mapped|1 target controls covered
3%
NIST AI Risk Management Framework (AI RMF 1.0)
1 source controls mapped|1 target controls covered
3%
ISO 41001:2018 - Facility Management Systems
1 source controls mapped|2 target controls covered
3%
ISO 39001:2012 - Road Traffic Safety Management
1 source controls mapped|2 target controls covered
3%
ISO 22313:2020 - Guidance on Business Continuity Management Systems
1 source controls mapped|2 target controls covered
3%
ISO 26000:2010
1 source controls mapped|1 target controls covered
3%
NIST SP 1800-32
1 source controls mapped|3 target controls covered
3%
ISO 20400:2017 - Sustainable Procurement
1 source controls mapped|3 target controls covered
3%
ISO 22317
1 source controls mapped|1 target controls covered
3%
ISO 22318
1 source controls mapped|1 target controls covered
3%
ISO 27019
1 source controls mapped|3 target controls covered
3%
ISO 22316
1 source controls mapped|1 target controls covered
3%
ISO/IEC 27006:2024
1 source controls mapped|1 target controls covered
3%
Secure by Design: A Guide for Manufacturers (CISA)
1 source controls mapped|1 target controls covered
3%
Oman National Cybersecurity Framework
1 source controls mapped|1 target controls covered
3%
NIST SP 800-66
1 source controls mapped|1 target controls covered
3%
New Zealand Information Security Manual (NZISM)
1 source controls mapped|1 target controls covered
3%
MDS2 (Medical Device)
1 source controls mapped|1 target controls covered
3%
MARS-E
1 source controls mapped|1 target controls covered
3%
IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2)
1 source controls mapped|1 target controls covered
3%
IATA Operational Safety Audit (IOSA) Standards Manual
1 source controls mapped|1 target controls covered
3%
FTC GLBA Safeguards Rule (16 CFR Part 314)
1 source controls mapped|1 target controls covered
3%
ASD Strategies to Mitigate Cyber Security Incidents
1 source controls mapped|1 target controls covered
3%
ISO 27799
1 source controls mapped|1 target controls covered
3%
ISO 13485
1 source controls mapped|1 target controls covered
3%

Frequently Asked Questions

What is Space ISAC (Information Sharing and Analysis Center) - Threat Framework?

Space ISAC (Information Sharing and Analysis Center) - Threat Framework is a compliance framework from International (Space Industry) with 24 domains and 40 controls. The Space Information Sharing and Analysis Center (Space ISAC), launched in 2019 and operational from 2020, provides threat intelligence, vulnerability coordination, and incident response support for the global space industry. Housed at the National Cybersecurity Center in Colorado Springs. Members include satellite operators, launch providers, ground system operators, and space-related government agencies. The Space ISAC threat framework categorises space-specific cyber and physical threats, provides indicators of compromise (IOCs), and coordinates vulnerability disclosure for space systems. Key focus areas include: ground segment cyber threats, space segment RF/cyber attacks, supply chain integrity, and space weather impacts. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does Space ISAC (Information Sharing and Analysis Center) - Threat Framework have?

Space ISAC (Information Sharing and Analysis Center) - Threat Framework has 40 controls organised across 24 domains. The largest domains are Communications Link Threats (4 controls), Governance and Collective Security (4 controls), Ground Segment Threats (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does Space ISAC (Information Sharing and Analysis Center) - Threat Framework map to?

Space ISAC (Information Sharing and Analysis Center) - Threat Framework maps to 84 other compliance frameworks. The top mapping partners are ISO/IEC 27011:2024 (10% coverage), NIST Cybersecurity Framework 2.0 (8% coverage), OWASP DevSecOps Maturity Model (DSOMM) (8% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with Space ISAC (Information Sharing and Analysis Center) - Threat Framework compliance?

Start your Space ISAC (Information Sharing and Analysis Center) - Threat Framework compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Space ISAC (Information Sharing and Analysis Center) - Threat Framework requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 40 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required