01
FUNCTION 05FUNCTION 04FUNCTION 03FUNCTION 02CONCEPT OFOPERATIONSFUNCTION 01
Function One
CONCEPT OF
OPERATIONS

Master Decomposition.

“The adversary suffers when you know your platform better than they ever can.”

You lead SCOR, Kestrel Orbital’s new Space Cybersecurity Operations and Resilience department, and its mission is to evolve the three platform departments (Security Operations, Satellite Operations, and Satellite Design & Engineering) toward resilient cyber operations. Today you put in place the first piece of that mission’s means, the centralized taxonomy, ontology, and enumeration process, by decomposing the telecommand path into enumerated elements.

DOWNLOAD THE WORKBOOKOpen it now and follow along. It carries the depth this deck does not. COURSE SLIDES · 45 MIN
MODULE ONE
01/28
02
DAY 1

DAY 1 START

The people. Day one at Kestrel Orbital. You work with Theo Lindgren, senior controller in the Satellite Operations Center, who flies this platform every pass, and Dana Whitfield, systems engineer in Satellite Design & Engineering, who built it. Between them they know this platform better than anyone at Kestrel Orbital, and they have never written it down the same way.

The mandates. Executive Order 14144 sets the command-and-control protections civil space systems are held to: encrypt the commands, protect their integrity, authenticate the source, and reject unauthorized commands. The NIS2 Directive puts the ground-based infrastructure that carries it under mandatory cybersecurity risk-management and reporting duties. Kestrel Orbital’s own executive memorandum adds the third: machine-to-machine sharing with the Space ISAC.

The scope. Why the telecommand path first? Because the mandates land on it. The path that keeps the satellite under control is the path you must be able to show is protected, so that is where your decomposition starts.

MODULE ONE
02/28
03

DAY 1

Today you build the Day-1 CONOPS: the telecommand path decomposed into 44 enumerated elements all three departments read the same way.

Your role
One shared description of the telecommand path, so Security Operations, Satellite Operations and Satellite Design & Engineering can respond in a concerted manner instead of three. Three mandates set the scope: EO 14144 on protecting command and control, NIS2 on reporting incidents to the thresholds the directive sets, and the Space ISAC exchange on sharing what is confirmed, redacted and machine to machine.
Today, Day 1
Decompose the telecommand path across the four layers, so all three departments can act on what you write. Environments and segments complete; services and assets a first tranche.
The week ahead
Day 2 threats, Day 3 attack paths and data, Day 4 detections and response, Day 5 defenses that take options away.
PCE-TE
Terrestrial
Terrestrial operational regime: ground-station facility with parabolic and phased-array antennas at dusk
PCE-AQ
Aquatic
Aquatic operational regime: downrange telemetry tracking vessel at sea with radar dome and satellite tracking antennas
PCE-AE
Aerial
Aerial operational regime: high-altitude long-endurance aircraft in the upper atmosphere with stratospheric horizon below
PCE-OR
Orbital
Orbital operational regime: GEO communications satellite over Earth at orbital sunset, solar arrays deployed
PCE-DS
Deep Space
Deep-space operational regime: cislunar or interplanetary probe with high-gain dish pointed back toward distant Earth
FULL SPECTRUM SPACE CYBERSECURITY PROFESSIONAL
The framework spans all five operational environments; this pass uses two
Full Spectrum Space Cybersecurity Professional at a security-operations workstation with multiple screens showing live operational views of all five environments: terrestrial ground station, aquatic tracking vessel, aerial high-altitude platform, orbital satellite, and deep-space probe
MODULE ONE
03/28
04
Kestrel OrbitalOrientation

CHECKPOINT

5 questions on the job you were hired into
01The organization02The department you lead03The three departments you align04The problem you were brought in to solve05The scope that sets Day 1

Confirm the context before you take on the data model.

MODULE ONE
04/28
05
Learn

Data Model

One standard data model for Kestrel Orbital's platform. Every part you enumerate resolves to a single element in one of four layers (PCE, SEG, SVC, AST), so the three departments describe the same platform the same way. You learn the model's two halves, the taxonomy and the ontology, then the two forms every element is written in: the published type name you read, and the enumerated name you apply to one real instance.

MODULE ONE
05/28
06
Learn

ONE DATA MODEL FOR TAXONOMY AND ONTOLOGY

The problem
Three departments name the same element differently, so what one knows does not carry to the other two.
Taxonomy · the words
Every element is named from the published list, never invented, so all three departments name the same part the same way.
Ontology · the parent chain
Every element below the environment layer links up to its parent: Asset to Service to Segment to Environment. Environments are the root and take no parent, so nothing floats. This is the parent chain, and it is not the same thing as the chain you meet on Day 2.
▷ THE FOUR DECOMPOSITION LAYERS · every published TEN on the right; click an element for its full TEN
PCEcontains segments5 published
Operational zone in which a capability primarily exists or is exercised.
Root of the chain. No link above it.
SEGcontains services10 published
Service and asset enclaves that compose the system across environments.
SVCcontains assets3 published
Functional planes that organize control and data responsibilities.
ASTthe concrete parts6 published
Asset classes composing the system and its interfaces.
Solid amber · will be enumerated on the telecommand path
Dashed grey · published, reference only
One taxonomy, shared beyond Kestrel Orbital: Space ISAC sharing is a company mandate, and these published names make it work machine to machine.
PCEPRIMARY CAPABILITY ENVIRONMENT LAYER
SEGSEGMENT LAYER
SVCSERVICE LAYER
ASTASSET LAYER
MODULE ONE
06/28
07
Learn

READ AND APPLY THE DATA MODEL

Reading the data model means reading an element’s published type name, its Taxonomic Element Nomenclature (TEN). Applying it means producing the Enumerated Taxonomic Element Nomenclature (ETEN) that names one specific instance on the platform you operate. Below, one element read, then applied.

TEN · you read it
Four hyphenated fields, LAYER-TAG-LABEL-Definition, naming a type. Published, never invented.
ETEN · you produce it
Five colon fields, LAYER:TAG:LABEL:ORDINAL:Description, naming one instance. Cited on tickets, diagrams, and detections alike.
Ordinal and Description make it specific
LAYER, TAG, and LABEL carry over from the TEN; you add the ordinal and the scoping sentence.
▷ ONE WORKED ELEMENT · click any field for its rule
Read · TEN · the published type
Same element, applied: keep layer, tag, and label; add the ordinal and the Description.
Apply · ETEN · one instance on Kestrel Orbital
TEN · LAYER

Which of the four decomposition layers the type sits in. Root layer here: the environment the platform operates in.

MODULE ONE
07/28
08
Apply

THE ETEN PROCESS · EIGHT STEPS

One process, four layers. Every element in the CONOPS is produced by the same eight steps, in fixed order, walked once per instance; the dashed loop is the walk repeating until a layer is fully enumerated. It builds the 44-element deliverable: 4 PCE + 4 SEG + 15 SVC + 21 AST, every parent link populated below the root, no orphans.

PCE layer · shown at one layer on purpose, walked deep so you hold the eight steps; the At-layer deltas on steps 06 and 07 carry everything the lower layers change. Click a step for its rule.
↻ repeat per instance until the layer is fully enumerated
▷ The process
STEP 01 OF 08
01Set the SCOPE

Set the boundary of the enumeration from the resilience objective and the requirements that drive the decomposition. An element outside this scope is not enumerated.

▷ Example from the course

The command-and-control mission the three mandates hold Kestrel Orbital to gives the Day-1 CONOPS its scope: the telecommand path, everything that carries, authorizes, or executes a command, and nothing else.

MODULE ONE
08/28
09
Kestrel OrbitalLearn

CHECKPOINT

5 questions on the data model
01The taxonomy that names every part02The ontology that links them03The four decomposition layers04Why one shared data model matters

Confirm the foundation before you decompose the first layer.

MODULE ONE
09/28
10
Learn

CONOPS

The Concept of Operations: the platform decomposed into its four layers, root first. You walk Environment, then Segment, Service, and Asset; at each layer you meet the enumerated elements the departments produced with the eight-step process, and a checkpoint closes the layer. By the last one the Day-1 CONOPS holds all 44 elements, every parent link populated below the root.

MODULE ONE
10/28
11
Layer 1 of 4

ENVIRONMENT LAYER

Where a space system operates: Terrestrial, Aquatic, Aerial, Orbital, and Deep Space. Naming the environment first is what an inventory that starts at the asset cannot give you: it records the where, never the things inside it, and every element below inherits that context, the zone, jurisdiction, and physics a finding lives in. On the telecommand path you enumerate four environments: two terrestrial sites and two orbital regimes.

MODULE ONE
11/28
12
Apply

ENVIRONMENTS ENUMERATED · 4 ELEMENTS

Every environment on the telecommand path, produced by the eight-step process with the three departments in the room. Click a TAG to page through its enumerated instances.

2 of 4 PCE elements
PCE-OR-Orbital-Operational zones within planetary or satellite orbits.
Geostationary orbit regime (GEO) the fleet flies inEnvironment
PCE:OR:Orbital:00
Geostationary orbit regime (GEO) the fleet flies in
The geostationary orbit regime (~35,786 km) part of the fleet flies in, fixing its coverage geometry, contact windows, and radiation exposure.
Medium Earth orbit regime (MEO) the fleet flies inEnvironment
PCE:OR:Orbital:01
Medium Earth orbit regime (MEO) the fleet flies in
The medium Earth orbit regime (~8,000 km) part of the fleet flies in, with its own orbital periods, contact windows, and radiation environment.
Click an element for its full record: name spelled out, definition, and sources
MODULE ONE
12/28
13
Kestrel OrbitalLearn

CHECKPOINT

5 questions on what the Primary Capability Environment layer adds
01Naming the environment the platform operates in02The context every other element inherits

Answer to confirm the section landed before you move on to the Segment layer.

MODULE ONE
13/28
14
Layer 2 of 4

SEGMENT LAYER

The enclaves that compose the platform. The published taxonomy defines ten segment types: Launch, Link, Ground, User, Aquatic, Low Altitude, High Altitude, Near Space, Space, and Deep Space. Naming the segment tells all three departments which enclave a finding lives in, and every segment links up to one or more environments. Kestrel’s telecommand scope enumerates four segments across three TAGs: Space, Link, and two Ground.

MODULE ONE
14/28
15
Apply

SEGMENTS ENUMERATED · 4 ELEMENTS

Every segment on the telecommand path, each linking up to the environments it spans. Click a TAG to page through its enumerated instances.

1 of 4 SEG elements
SEG-SP-Space-Services and assets operating in planetary or satellite orbits.
Platform subsystems on orbitSpace
SEG:SP:Space:00
Platform subsystems on orbit
The on-orbit enclave: the flight services and their assets operating on the constellation spacecraft, beyond physical reach.
Click an element for its full record: name spelled out, definition, and sources
MODULE ONE
15/28
16
Kestrel OrbitalLearn

CHECKPOINT

5 questions on the Segment layer
01The enclaves the platform is distributed into02How each links up to its environment

Answer to confirm the section landed before you move on to the Service layer.

MODULE ONE
16/28
17
Layer 3 of 4

SERVICE LAYER

What runs on the platform: Control Plane, Data Plane, and Hybrid. A service is a functional responsibility, what the platform does, not the box it runs on, which is why the Security Operations Center writes detection rules here: a detection written against a service stays valid as the assets implementing it change, so it survives a hardware refresh. The telecommand scope enumerates fifteen services across the Space, Link, and Ground segments.

MODULE ONE
17/28
18
Apply

SERVICES ENUMERATED · 15 ELEMENTS

The services enumerated on the telecommand path in this pass, named by responsibility so detections target the function, not the box. Launch-phase services and the payload chain are out of this pass on purpose: the fleet is already flying, and Executive Order 14144 puts the command and control of an operational platform first. They follow the same procedure when their turn comes. Click a TAG to page through its enumerated instances.

10 of 15 SVC elements
SVC-CP-Control Plane-Services for managing and orchestrating platform control functions.
ADCSSpace
SVC:CP:Control Plane:00
ADCS
The service that determines and controls spacecraft orientation (ADCS).
Crypto (Space)Space
SVC:CP:Control Plane:01
Crypto (Space)
The service that encrypts and authenticates on board, including telecommand authentication (Crypto, space).
EPSSpace
SVC:CP:Control Plane:02
EPS
The service that generates, stores, and distributes electrical power (EPS).
TCSSpace
SVC:CP:Control Plane:04
TCS
The service that holds every component within its temperature limits (TCS).
ACA (Link)Link
SVC:CP:Control Plane:05
ACA (Link)
The service that authenticates command sources and enforces command acceptance on the uplink (ACA, link).
Attack Detection / RecoverySpace
SVC:CP:Control Plane:06
Attack Detection / Recovery
The service that detects hostile command or state manipulation on board and recovers from it.
Crypto (Ground)Ground
SVC:CP:Control Plane:08
Crypto (Ground)
The service that protects commands before uplink and data after downlink (Crypto, ground).
ACA (Ground)Ground
SVC:CP:Control Plane:09
ACA (Ground)
The service that decides who may command and which commands are released to the link (ACA, ground).
Patch UpdatesGround
SVC:CP:Control Plane:12
Patch Updates
The service that delivers and installs software and firmware updates under control (Patch Updates).
Satellite ConsoleGround
SVC:CP:Control Plane:13
Satellite Console
The service that gives operators the mission-ops console: telemetry monitoring and command issue.
Click an element for its full record: name spelled out, definition, and sources
MODULE ONE
18/28
19
Kestrel OrbitalLearn

CHECKPOINT

5 questions on the Service layer
01All three service types are in scope on the telecommand path02The function each enclave delivers03How services link up to segments

Answer to confirm the section landed before you move on to the Asset layer.

MODULE ONE
19/28
20
Layer 4 of 4

ASSET LAYER

The individual parts: Hardware, Firmware, Software, Data, Signal, and Hybrid. This is where the three departments converge and the work happens: patches land on assets, detections fire on assets, anomalies surface on assets, and each asset links up to every service it carries, so its full chain reads straight up and a shared box shows every service that falls with it. The telecommand scope enumerates twenty-one assets.

MODULE ONE
20/28
21
Apply

ASSETS ENUMERATED · 21 ELEMENTS

The assets enumerated on the telecommand path in this pass, each naming every service it implements. Click a TAG to page through its enumerated instances.

7 of 21 AST elements
AST-HW-Hardware-Physical components supporting platform operations.
ADCS sensorsSpace
AST:HW:Hardware:00
ADCS sensors
The physical attitude sensors: star trackers, sun sensors, gyros, magnetometers.
EPS power chainSpace
AST:HW:Hardware:01
EPS power chain
The physical power chain: solar arrays, batteries, power distribution.
Thermal control hardwareSpace
AST:HW:Hardware:03
Thermal control hardware
The physical thermal hardware: heaters, radiators, coatings, insulation.
OBC + OBDH busSpace
AST:HW:Hardware:06
OBC + OBDH bus
The physical on-board computer and OBDH bus on each constellation spacecraft.
Operator consoleGround
AST:HW:Hardware:04
Operator console
The physical operator workstation from which telemetry is monitored and commands are issued.
Ground cryptographic module (HSM)Ground
AST:HW:Hardware:05
Ground cryptographic module (HSM)
The physical ground cryptographic module (HSM) that stores ground keys and performs encryption, decryption, signing, and verification.
Kiruna antenna and RF front endGround
AST:HW:Hardware:08
Kiruna antenna and RF front end
The physical Kiruna antenna, feed, and low-noise / high-power RF front end.
Click an element for its full record: name spelled out, definition, and sources
MODULE ONE
21/28
22
Kestrel OrbitalLearn

CHECKPOINT

5 questions on the Asset layer
01All six asset types are in scope on this path02The concrete elements that implement each service03How they link up

Answer to confirm the section landed before you validate the decomposition and present the CONOPS.

MODULE ONE
22/28
23
Build

CONOPS Presentation

You present the validated telecommand decomposition to the three departments: every asset traces to a service, a segment, and an environment, with no orphans. An unbroken parent chain is what makes the decomposition usable as evidence, enrichment on any element carries its full structural context, and the elements the three mandates concern can be produced on demand.

MODULE ONE
23/28
24
PRESENT

THE CONOPS · OVERVIEW

Segments
SPACE
6 services · 9 assets
▸ expand
LINK
4 services · 4 assets
▸ expand
GROUND · RESTON
4 services · 7 assets
▸ expand
GROUND · KIRUNA
1 service · 1 asset
▸ expand
SEG
SEG:SP:Space:00
SEG:LI:Link:00
SEG:GR:Ground:00
SEG:GR:Ground:01
PCE
PCE:OR:Orbital:00
PCE:OR:Orbital:01
PCE:TE:Terrestrial:00
PCE:TE:Terrestrial:01
The telecommand path on one screen. Click any segment to expand its services and assets, every ETEN already visible; click a card to reveal its description.
MODULE ONE
24/28
25
Kestrel OrbitalApply

CHECKPOINT

5 questions on the deliverable you just built and presented
01Its counts02Its scope rule03Its parent links04How telecommand spans segments

Answer to confirm the catalogue holds up now that the room has seen it; your best score stays on this slide.

MODULE ONE
25/28
26
Apply

THEORY TO TOOLING

What you built today does not stay in the classroom. The METEORSTORM data model is a published taxonomy and ontology, and the moment the shift ends your work ships as machine tags readable by any operator running the same published taxonomy.

MODULE ONE
26/28
27
Entry point · Activate

ACTIVATE: DEPLOY THE TAXONOMY AND ONTOLOGY

Today you gave Kestrel Orbital one description of its telecommand path, written so all three departments read it without translation. Turning that data model on is governance work first and tooling second. Walk the journey: each stop is a document you update, and the last stop confirms you are ready.

UPDATE THE POLICY action
UPDATE THE PIRs action
UPDATE THE STANDARD action
UPDATE THE PROCEDURE action
YOU ARE READY TO GO action
01UPDATE THE POLICYAnchor the mandate: policy requires one shared platform data model across intelligence, operations, and engineering work.
▷ In the scenario

Kestrel Orbital’s security policy states the obligation Executive Order 14144 and the NIS2 Directive place on the company: the platform is described through one shared data model, every security activity anchors to it, and the taxonomy is how the standing Space ISAC sharing mandate is met.

▷ How your leads change
All three leads · Security, Operations, Engineering
Was Each department’s own description was its source of truth, and no document said otherwise.
Now One model is a company obligation, so a private departmental description no longer counts as the platform.
▷ Do this at your organization
  1. Name the driver. Write the regulatory obligations your platform carries into policy as the reason platform contextualization exists.
  2. Mandate the model. Policy requires one shared platform data model across security, operations, and engineering.
  3. Delegate downward. Policy points to the PIRs, the standard, and the procedure that implement it; each lower document cites the policy.
MIMISP
MODULE ONE
27/28
28
FUNCTION 05FUNCTION 04FUNCTION 03FUNCTION 02CONTEXTUALIZEDTHREAT MODELINGFUNCTION 02
Day 1 complete · threat modeling next

CONTEXTUALIZED
THREAT MODELING

Day 1 is complete: the telecommand path is decomposed into shared elements all three departments defend from one description. Tomorrow, Contextualized Threat Modeling anchors real adversary threats to what you built.

THE REAL PROBLEM
Three departments described the same platform three different ways. No one could name a part precisely, say what it connected to, or trace it to the environment it belonged in.
WHAT METEORSTORM DELIVERED
One shared CONOPS: the telecommand path decomposed top down into four environments, four segments, fifteen services and twenty-one assets, every child anchored to its parent.
THE KEY IMPROVEMENT

Point at an asset and read straight up to the service, segment and environment that own it, or down from an environment to the assets beneath it. From tomorrow, a threat, detection or defense enters the model only by naming a segment, service or asset.

END
MODULE ONE
28/28
REFERENCE LIBRARY

Standards, Policies & Sources

The instruments this course aligns to. Each instrument links to its primary source.

U.S. National Security Space Policy

CNSS Policy No. 12 (CNSSP-12)Information-assurance policy for national security space systems.CNSS Instruction 1200 (CNSSI 1200), Aug 2025Implementing requirements: on-board intrusion detection, hardware root-of-trust, patch management.DoDI 8581.01Information-assurance policy for space systems used by the DoD.Space Policy Directive 5 (SPD-5), 2020First comprehensive U.S. cybersecurity principles for space systems.

Executive Orders

EO 14144 (Jan 16, 2025)Strengthening and Promoting Innovation in the Nation’s Cybersecurity.EO 14306 (Jun 6, 2025)Sustaining select efforts, amending EO 13694 and EO 14144.

NIST Standards & FISMA

NIST SP 800-53 Rev. 5Security and privacy controls; IR-3 incident-response testing.NIST SP 800-37 Rev. 2Risk Management Framework; continuous monitoring and annual control assessment.NIST IR 8270Introduction to Cybersecurity for Commercial Satellite Operations.NIST IR 8401Satellite Ground Segment cybersecurity framework profile.NIST IR 8441Cybersecurity Framework Profile for Hybrid Satellite Networks.NIST SP 800-160 Vol. 2 Rev. 1Cyber resiliency goals: Anticipate, Withstand, Recover, Adapt.FISMAFederal Information Security Modernization Act; annual program review obligation.

Threat Frameworks (analytic layer)

MITRE ATT&CKAdversary tactics and techniques knowledge base.MITRE CAPECCommon Attack Pattern Enumeration and Classification; dictionary of attack patterns that exploit known weaknesses.MITRE D3FENDKnowledge graph of defensive countermeasures and techniques, mapped to ATT&CK (NSA-funded, maintained by MITRE).SPARTASpace Attack Research and Tactic Analysis (The Aerospace Corporation).ESA Space ShieldEuropean Space Agency space-system threat framework.

EU & Global

NIS2 Directive (EU 2022/2555)Risk management and 24h/72h incident reporting; space sector in scope.EU Space Act (proposal, 25 Jun 2025)Space-specific resilience and cybersecurity obligations; extraterritorial scope.ENISA Space Threat LandscapeEuropean threat landscape and recommendations for space operators.Cyber Resilience Act (CRA)Connected hardware/software requirements; applies from December 2027.

Open-Source Taxonomy & Tooling

METEORSTORM MISP taxonomyThe course taxonomy, live and open source in the MISP taxonomy repository.MISP / CIRCLComputer Incident Response Center Luxembourg, maintainers of MISP.RootAPublic-domain open detection language (YAML) used in Module 04 to write portable signatures. (github.com/UncoderIO/Roota)Uncoder.IOOpen-source IDE and translation engine that ports RootA rules across SIEM, EDR, and XDR formats.SpaceCOP & Indicators of BehaviorDHS S&T + Aerospace Corp. on-board intrusion-detection prototype.CROO (Cyber Resilience On-Orbit)Proof Labs on-board IDS for the Space Force.

Community & Reporting

Space ISACSpace Information Sharing and Analysis Center.Air & Space Forces MagazineWaterman, “New Cybersecurity Rules for Pentagon’s Commercial Satellite Vendors,” Nov 19, 2025.Via Satellite“DHS Wants Satellite Volunteers to Test New Cyber Tools,” Nov 17, 2025.Defense Daily“New National Space Cybersecurity Policy Emphasizes Intrusion Detection,” Nov 18, 2025.Mayer Brown legal analysis“Securing the Final Frontier,” Dec 11, 2025 (US and EU regulatory map).