# Response playbook for AN:DET:Detection Signature:00.
# Converted from the four-sentence pb object in det-inv.ts on 2026-08-08 under
# the response-playbook-raci ruling. Roles and authority levels are Module 7's:
# Mission Lead, Security Operations, Satellite Operations, at solo, collaborative
# or escalated. Every commanded action maps to one role at one level.
playbook: PB-00
name: Management-plane firmware-push abuse
covers: AN:DET:Detection Signature:00
tdm: SVC:CP:Control Plane:09
status: active
trigger: >
  AN:DET:Detection Signature:00 fires on an out-of-window firmware push at
  SVC:CP:Control Plane:09, at any confidence. The threshold is any confidence
  and not higher because the blast radius is the whole modem fleet.
roles:
    accountable: Mission Lead
    cyber: Security Operations
    space: Satellite Operations
actions:
    - id: ACT:00
      stage: assess
      domain: cyber
      action: Check the change record for a documented emergency change reference or an authorized red-team exercise covering this push window, the two benign causes the rule names.
      element: SVC:CP:Control Plane:09
      reversibility: reversible
      level: solo
      raci: { r: Security Operations, a: Mission Lead, c: [], i: [Satellite Operations] }
    - id: ACT:01
      stage: contain
      domain: cyber
      action: Revoke the pushing identity's command-release authority on the ground command-acceptance service.
      element: SVC:CP:Control Plane:09
      reversibility: reversible
      level: solo
      raci: { r: Security Operations, a: Mission Lead, c: [], i: [Satellite Operations] }
    - id: ACT:02
      stage: contain
      domain: cyber
      action: Halt the patch deployment pipeline carrying the image.
      element: AST:SW:Software:03
      reversibility: disruptive
      level: collaborative
      raci: { r: Security Operations, a: Mission Lead, c: [Satellite Operations], i: [] }
    - id: ACT:03
      stage: recover
      domain: cyber
      action: Inventory which terminals received the push and compare each deployed firmware hash against the signed expected value.
      element: AST:SW:Software:03
      reversibility: reversible
      level: solo
      raci: { r: Security Operations, a: Mission Lead, c: [], i: [Satellite Operations] }
    - id: ACT:04
      stage: recover
      domain: space
      action: Sequence the rollback of affected terminals against the maintenance window, confirming operational impact before each batch.
      element: AST:SW:Software:03
      why: Changes what the terminal fleet is running and when, a mission operational state change taken on a ground element.
      reversibility: disruptive
      level: collaborative
      raci: { r: Satellite Operations, a: Mission Lead, c: [Security Operations], i: [] }
    - id: ACT:05
      stage: report
      domain: cyber
      action: Notify the duty officer and the CISO immediately, and start the NIS2 clocks on awareness, 24-hour early warning, 72-hour notification, one-month final report. A fleet-wide firmware event is significant on its face, so significance is pre-determined here and does not wait on a call.
      element: SVC:CP:Control Plane:09
      reversibility: reversible
      level: solo
      raci: { r: Security Operations, a: Mission Lead, c: [], i: [Satellite Operations] }
    - id: ACT:06
      stage: report
      domain: cyber
      action: File the redacted Space ISAC Exchange entry.
      element: SVC:CP:Control Plane:09
      reversibility: irreversible
      level: escalated
      raci: { r: Security Operations, a: Mission Lead, c: [Satellite Operations], i: [] }
