Master Decomposition.
“The adversary suffers when you know your platform better than they ever can.”
You lead SCOR, Kestrel Orbital’s new Space Cybersecurity Operations and Resilience department, and its mission is to evolve the three platform departments (Security Operations, Satellite Operations, and Satellite Design & Engineering) toward resilient cyber operations. Today you put in place the first piece of that mission’s means, the centralized taxonomy, ontology, and enumeration process, by decomposing the telecommand path into enumerated elements.
DAY 1 START
The people. Day one at Kestrel Orbital. You work with Theo Lindgren, senior controller in the Satellite Operations Center, who flies this platform every pass, and Dana Whitfield, systems engineer in Satellite Design & Engineering, who built it. Between them they know this platform better than anyone at Kestrel Orbital, and they have never written it down the same way.
The mandates. Executive Order 14144 sets the command-and-control protections civil space systems are held to: encrypt the commands, protect their integrity, authenticate the source, and reject unauthorized commands. The NIS2 Directive puts the ground-based infrastructure that carries it under mandatory cybersecurity risk-management and reporting duties. Kestrel Orbital’s own executive memorandum adds the third: machine-to-machine sharing with the Space ISAC.
The scope. Why the telecommand path first? Because the mandates land on it. The path that keeps the satellite under control is the path you must be able to show is protected, so that is where your decomposition starts.
DAY 1
Today you build the Day-1 CONOPS: the telecommand path decomposed into 44 enumerated elements all three departments read the same way.






OrientationCHECKPOINT
01The organization02The department you lead03The three departments you align04The problem you were brought in to solve05The scope that sets Day 1Confirm the context before you take on the data model.
Data Model
One standard data model for Kestrel Orbital's platform. Every part you enumerate resolves to a single element in one of four layers (PCE, SEG, SVC, AST), so the three departments describe the same platform the same way. You learn the model's two halves, the taxonomy and the ontology, then the two forms every element is written in: the published type name you read, and the enumerated name you apply to one real instance.
ONE DATA MODEL FOR TAXONOMY AND ONTOLOGY
PCEcontains segments5 publishedSEGcontains services10 publishedSVCcontains assets3 publishedASTthe concrete parts6 publishedDashed grey · published, reference only
PCEPRIMARY CAPABILITY ENVIRONMENT LAYERSEGSEGMENT LAYERSVCSERVICE LAYERASTASSET LAYERREAD AND APPLY THE DATA MODEL
Reading the data model means reading an element’s published type name, its Taxonomic Element Nomenclature (TEN). Applying it means producing the Enumerated Taxonomic Element Nomenclature (ETEN) that names one specific instance on the platform you operate. Below, one element read, then applied.
LAYER-TAG-LABEL-Definition, naming a type. Published, never invented.LAYER:TAG:LABEL:ORDINAL:Description, naming one instance. Cited on tickets, diagrams, and detections alike.Which of the four decomposition layers the type sits in. Root layer here: the environment the platform operates in.
THE ETEN PROCESS · EIGHT STEPS
One process, four layers. Every element in the CONOPS is produced by the same eight steps, in fixed order, walked once per instance; the dashed loop is the walk repeating until a layer is fully enumerated. It builds the 44-element deliverable: 4 PCE + 4 SEG + 15 SVC + 21 AST, every parent link populated below the root, no orphans.
Set the boundary of the enumeration from the resilience objective and the requirements that drive the decomposition. An element outside this scope is not enumerated.
The command-and-control mission the three mandates hold Kestrel Orbital to gives the Day-1 CONOPS its scope: the telecommand path, everything that carries, authorizes, or executes a command, and nothing else.
LearnCHECKPOINT
01The taxonomy that names every part02The ontology that links them03The four decomposition layers04Why one shared data model mattersConfirm the foundation before you decompose the first layer.
CONOPS
The Concept of Operations: the platform decomposed into its four layers, root first. You walk Environment, then Segment, Service, and Asset; at each layer you meet the enumerated elements the departments produced with the eight-step process, and a checkpoint closes the layer. By the last one the Day-1 CONOPS holds all 44 elements, every parent link populated below the root.
ENVIRONMENT LAYER
Where a space system operates: Terrestrial, Aquatic, Aerial, Orbital, and Deep Space. Naming the environment first is what an inventory that starts at the asset cannot give you: it records the where, never the things inside it, and every element below inherits that context, the zone, jurisdiction, and physics a finding lives in. On the telecommand path you enumerate four environments: two terrestrial sites and two orbital regimes.
ENVIRONMENTS ENUMERATED · 4 ELEMENTS
Every environment on the telecommand path, produced by the eight-step process with the three departments in the room. Click a TAG to page through its enumerated instances.
PCE-OR-Orbital-Operational zones within planetary or satellite orbits.
EnvironmentPCE:OR:Orbital:00
EnvironmentPCE:OR:Orbital:01
LearnCHECKPOINT
01Naming the environment the platform operates in02The context every other element inheritsAnswer to confirm the section landed before you move on to the Segment layer.
SEGMENT LAYER
The enclaves that compose the platform. The published taxonomy defines ten segment types: Launch, Link, Ground, User, Aquatic, Low Altitude, High Altitude, Near Space, Space, and Deep Space. Naming the segment tells all three departments which enclave a finding lives in, and every segment links up to one or more environments. Kestrel’s telecommand scope enumerates four segments across three TAGs: Space, Link, and two Ground.
SEGMENTS ENUMERATED · 4 ELEMENTS
Every segment on the telecommand path, each linking up to the environments it spans. Click a TAG to page through its enumerated instances.
SEG-SP-Space-Services and assets operating in planetary or satellite orbits.
SpaceSEG:SP:Space:00
LearnCHECKPOINT
01The enclaves the platform is distributed into02How each links up to its environmentAnswer to confirm the section landed before you move on to the Service layer.
SERVICE LAYER
What runs on the platform: Control Plane, Data Plane, and Hybrid. A service is a functional responsibility, what the platform does, not the box it runs on, which is why the Security Operations Center writes detection rules here: a detection written against a service stays valid as the assets implementing it change, so it survives a hardware refresh. The telecommand scope enumerates fifteen services across the Space, Link, and Ground segments.
SERVICES ENUMERATED · 15 ELEMENTS
The services enumerated on the telecommand path in this pass, named by responsibility so detections target the function, not the box. Launch-phase services and the payload chain are out of this pass on purpose: the fleet is already flying, and Executive Order 14144 puts the command and control of an operational platform first. They follow the same procedure when their turn comes. Click a TAG to page through its enumerated instances.
SVC-CP-Control Plane-Services for managing and orchestrating platform control functions.
SpaceSVC:CP:Control Plane:00
SpaceSVC:CP:Control Plane:01
SpaceSVC:CP:Control Plane:02
SpaceSVC:CP:Control Plane:04
LinkSVC:CP:Control Plane:05
SpaceSVC:CP:Control Plane:06
GroundSVC:CP:Control Plane:08
GroundSVC:CP:Control Plane:09
GroundSVC:CP:Control Plane:12
GroundSVC:CP:Control Plane:13
LearnCHECKPOINT
01All three service types are in scope on the telecommand path02The function each enclave delivers03How services link up to segmentsAnswer to confirm the section landed before you move on to the Asset layer.
ASSET LAYER
The individual parts: Hardware, Firmware, Software, Data, Signal, and Hybrid. This is where the three departments converge and the work happens: patches land on assets, detections fire on assets, anomalies surface on assets, and each asset links up to every service it carries, so its full chain reads straight up and a shared box shows every service that falls with it. The telecommand scope enumerates twenty-one assets.
ASSETS ENUMERATED · 21 ELEMENTS
The assets enumerated on the telecommand path in this pass, each naming every service it implements. Click a TAG to page through its enumerated instances.
AST-HW-Hardware-Physical components supporting platform operations.
SpaceAST:HW:Hardware:00
SpaceAST:HW:Hardware:01
SpaceAST:HW:Hardware:03
SpaceAST:HW:Hardware:06
GroundAST:HW:Hardware:04
GroundAST:HW:Hardware:05
GroundAST:HW:Hardware:08
LearnCHECKPOINT
01All six asset types are in scope on this path02The concrete elements that implement each service03How they link upAnswer to confirm the section landed before you validate the decomposition and present the CONOPS.
CONOPS Presentation
You present the validated telecommand decomposition to the three departments: every asset traces to a service, a segment, and an environment, with no orphans. An unbroken parent chain is what makes the decomposition usable as evidence, enrichment on any element carries its full structural context, and the elements the three mandates concern can be produced on demand.
THE CONOPS · OVERVIEW
ApplyCHECKPOINT
01Its counts02Its scope rule03Its parent links04How telecommand spans segmentsAnswer to confirm the catalogue holds up now that the room has seen it; your best score stays on this slide.
THEORY TO TOOLING
What you built today does not stay in the classroom. The METEORSTORM data model is a published taxonomy and ontology, and the moment the shift ends your work ships as machine tags readable by any operator running the same published taxonomy.
ACTIVATE: DEPLOY THE TAXONOMY AND ONTOLOGY
Today you gave Kestrel Orbital one description of its telecommand path, written so all three departments read it without translation. Turning that data model on is governance work first and tooling second. Walk the journey: each stop is a document you update, and the last stop confirms you are ready.





Kestrel Orbital’s security policy states the obligation Executive Order 14144 and the NIS2 Directive place on the company: the platform is described through one shared data model, every security activity anchors to it, and the taxonomy is how the standing Space ISAC sharing mandate is met.
- Name the driver. Write the regulatory obligations your platform carries into policy as the reason platform contextualization exists.
- Mandate the model. Policy requires one shared platform data model across security, operations, and engineering.
- Delegate downward. Policy points to the PIRs, the standard, and the procedure that implement it; each lower document cites the policy.
CONTEXTUALIZED
THREAT MODELING
Day 1 is complete: the telecommand path is decomposed into shared elements all three departments defend from one description. Tomorrow, Contextualized Threat Modeling anchors real adversary threats to what you built.
Point at an asset and read straight up to the service, segment and environment that own it, or down from an environment to the assets beneath it. From tomorrow, a threat, detection or defense enters the model only by naming a segment, service or asset.