# Response playbook for AN:DET:Detection Signature:03. See PB-00 header for provenance.
# GAP-BLOCKED. Function 03 recorded the required source as a Gap: measured boot
# is not flown. The signature is dormant and this playbook still ships, complete
# and validated, so the authorized response exists the day the source arrives
# rather than being written under pressure then.
playbook: PB-03
name: Firmware-hash mismatch at boot
covers: AN:DET:Detection Signature:03
tdm: AST:FW:Firmware:01
status: gap-blocked
gap:
    reason: Measured boot is not flown, so the signature cannot fire.
    owner: Satellite Design and Engineering
trigger: >
  AN:DET:Detection Signature:03 fires on a measured-hash mismatch at
  AST:FW:Firmware:01 at boot or after an update, at any confidence. The
  threshold is any confidence because an unauthorized image running on the
  on-board computer admits no benign cause. Dormant until measured boot ships.
roles:
    accountable: Mission Lead
    cyber: Security Operations
    space: Satellite Operations
actions:
    - id: ACT:00
      stage: assess
      domain: space
      action: Compare the measured hash against the signed expected value in the vendor manifest.
      element: AST:FW:Firmware:01
      reversibility: reversible
      level: solo
      raci: { r: Satellite Operations, a: Mission Lead, c: [], i: [Security Operations] }
    - id: ACT:01
      stage: contain
      domain: space
      action: Hold the boot firmware in its current state and keep it out of an operational role.
      element: AST:FW:Firmware:01
      reversibility: disruptive
      level: collaborative
      raci: { r: Satellite Operations, a: Mission Lead, c: [Security Operations], i: [] }
    - id: ACT:02
      stage: contain
      domain: space
      action: Switch to the redundant on-board computer where one exists.
      element: AST:HW:Hardware:06
      reversibility: irreversible
      level: escalated
      raci: { r: Satellite Operations, a: Mission Lead, c: [Security Operations], i: [] }
    - id: ACT:03
      stage: recover
      domain: cyber
      action: Engage the flight-software build team on the source of the discrepancy and audit the patch deployment pipeline for the image's provenance.
      element: AST:SW:Software:03
      reversibility: reversible
      level: solo
      raci: { r: Security Operations, a: Mission Lead, c: [], i: [Satellite Operations] }
    - id: ACT:04
      stage: recover
      domain: space
      action: Re-establish a known-good image before the component resumes its role.
      element: AST:FW:Firmware:01
      reversibility: irreversible
      level: escalated
      raci: { r: Satellite Operations, a: Mission Lead, c: [Security Operations], i: [] }
    - id: ACT:05
      stage: report
      domain: cyber
      action: Notify the duty officer and the CISO. A confirmed unauthorized on-orbit image is a significant incident, so the NIS2 24-hour early warning starts on confirmation, with the 72-hour notification and one-month final report following.
      element: AST:FW:Firmware:01
      why: Reporting is an information act carried out by Security Operations; the element names what the report concerns, not where the action lands.
      reversibility: reversible
      level: solo
      raci: { r: Security Operations, a: Mission Lead, c: [], i: [Satellite Operations] }
    - id: ACT:06
      stage: report
      domain: cyber
      action: Engage the supply-chain lead upstream and file the redacted Space ISAC Exchange entry.
      element: AST:SW:Software:03
      reversibility: irreversible
      level: escalated
      raci: { r: Security Operations, a: Mission Lead, c: [Satellite Operations], i: [] }
