Space Cybersecurity Risk Assessment NIST SP 800-53 MITRE ATLAS

SOCRM

Space Optical Communications Cyber Risk Mapper. An interactive decision-support tool assessing cybersecurity risks for optical and hybrid RF/optical space communication architectures supporting lunar, cislunar, and deep-space missions.

Domain
Space Communications
Context
NASA Artemis II O2O
Threat Vectors
10 Categories
Frameworks
NIST + ATLAS
Launch Dashboard → View Source

As NASA's Artemis II mission deploys the Orion Optical Communications System (O2O) to demonstrate laser-based data links from the Moon, the cybersecurity community faces a critical question: what new threat surfaces emerge when we shift from radio frequency to optical communications in space?

SOCRM addresses this by providing a configurable risk assessment engine that maps 10 threat categories across mission parameters, communication architectures, and operational environments, producing quantified risk scores with NIST SP 800-53 control mappings and MITRE ATLAS alignment.

-70%
Interception risk reduction with optical vs RF architectures
-55%
Jamming exposure reduction with optical communications
+45%
New attack surface from precision pointing (PAT) system disruption
10
Threat categories modeled with NIST SP 800-53 control mappings
Threat Vector RF Risk Optical Risk Delta Segment
Signal Interception85%15%▼ 70%Link
Communication Jamming80%25%▼ 55%Link
Signal Spoofing70%20%▼ 50%Link
Endpoint Compromise65%60%▼ 5%Space / Ground
Optical Terminal Misalignment10%55%▲ 45%Space
Supply Chain Insertion50%50%— 0%All
Key Management Failure55%45%▼ 10%All
AI Decision Manipulation40%40%— 0%Space / Ground
Data Integrity Loss60%30%▼ 30%Link
Ground Segment Compromise75%65%▼ 10%Ground
RiskScore = BaseThreatScore × EnvironmentMod × AutonomyMod × EncryptionMod × GroundTrustMod

Where BaseThreatScore is determined by communication type (RF, optical, or hybrid average). EnvironmentMod scales from LEO (0.7×) to Deep Space (1.15×). AutonomyMod adjusts for human-in-the-loop (0.8×) vs fully autonomous (1.25×). EncryptionMod ranges from QKD-enabled (0.4×) to no encryption (1.6×). GroundTrustMod spans SCIF-level (0.6×) to untrusted/contested (1.7×).

The interactive dashboard allows mission planners to configure: Mission type (crewed lunar, robotic lunar, LEO station, deep space probe), communication architecture (RF only, optical only, hybrid), operational environment (LEO, MEO/GEO, cislunar, deep space), autonomy level (manual, AI-assisted, fully autonomous), encryption posture (AES-256, post-quantum, QKD, none/legacy), and ground station trust (SCIF-level, commercial, shared/allied, untrusted).

Each configuration produces real-time composite risk scores, RF vs optical comparisons, detailed threat profiles with NIST and ATLAS mappings, and segment-level attack surface maps.

NIST SP 800-53 Rev. 5 MITRE ATLAS NIST CSF 2.0 Space Policy Directive 5 CCSDS

Every threat vector maps to specific NIST SP 800-53 security controls and MITRE ATLAS adversarial ML tactics. The framework identifies governance gaps in SPD-5 and CCSDS standards for optical link security, producing actionable mitigation recommendations for each threat category.

NASA's Artemis II mission carries the O2O laser communications payload, developed by MIT Lincoln Laboratory and NASA Goddard, capable of transmitting data at 260 Mbps via infrared laser links to ground terminals at White Sands, NM and Table Mountain, CA. This builds on the LLCD (2013), LCRD (2021), TBIRD (2022), and ILLUMA-T (2023) demonstrations.

Optical communications offer significant security advantages over RF: near-zero interception surface due to sub-arcsecond beam divergence, low probability of detection, and inherent resistance to broadband jamming. However, they also introduce new threat vectors including precision pointing disruption, atmospheric denial-of-service, concentrated ground terminal targeting, and novel supply chain risks in specialized optical components.