Overview
ISO/TS 20517:2024 - Space systems - Cybersecurity management requirements and recommendations - is a Technical Specification (first edition, July 2024) that defines management-level requirements and recommendations for cybersecurity in space systems. It applies to manned and unmanned spacecraft, launchers, payloads, experiments, ground equipment and other space facilities. The document focuses on systems engineering and product assurance activities to manage cyber risk across the space system life cycle; it does not provide detailed systems engineering or low-level cybersecurity technical procedures.
Key topics and technical requirements
ISO/TS 20517:2024 structures cybersecurity for space systems around practical management and systems-engineering concerns. Major topics include:
- Cybersecurity overview - contextualizing cyber risk at mission, programme and project levels.
- General principles - identify assets, define security perimeter, and describe the security environment (assets, entry points, external interactions).
- Cybersecurity management plan - requirement to develop and implement a plan that enables cyber risk assessment and selection of defence/mitigation techniques (includes safeguarding command/control, physical protection, anti‑jamming/spoofing, ground systems and OT protection).
- Policies and roles - responsibilities for cybersecurity among suppliers, prime contractors and programme/product assurance (PA).
- Requirements for cybersecurity - evaluation of all systems (including COTS/GOTS/MOTS, reused or autogenerated code, embedded software and programmable logic devices) for cyber risk.
- Cybersecurity process and culture - lifecycle-aligned processes, incident prevention/mitigation, and promoting cybersecurity awareness across organisations.
Key normative references include ISO 10795, ISO 14300-1/2, ISO 17666, ISO 18676 and ISO/IEC 27000.
Practical applications and who uses it
ISO/TS 20517:2024 is targeted at professionals responsible for managing cybersecurity across space projects:
- Systems engineers - to integrate cybersecurity into requirements, architecture and verification activities.
- Project and programme managers - to include cyber risk in project management plans and product assurance (PA).
- Software and safety engineers - to assess software supply-chain and runtime vulnerabilities (COTS, reused code, embedded systems).
- Operators and ground system managers - to define operational protections (command/telemetry, ground OT, anti‑spoofing/jamming).
- Quality and PA teams - to coordinate standards, risk assessments and assurance activities.
Use cases: developing a cybersecurity management plan, conducting system-level cyber risk assessments, defining supplier obligations, and aligning space projects with international cybersecurity and systems-engineering practices.
Related standards
Relevant references to align implementation include:
ISO/TS 20517:2024 provides a common management reference for the space sector to improve resilience, safety and trustworthiness of space systems through lifecycle-aligned cybersecurity practices.