Jose Ramon Coz Fernandez, Davide Senatori, Enrique Viudes Gutierrez
{"title":"Cybersecurity internal audit framework of the European Space Agency’s navigation satellite systems","authors":"Jose Ramon Coz Fernandez, Davide Senatori, Enrique Viudes Gutierrez","doi":"10.1016/j.jsse.2026.03.007","DOIUrl":null,"url":null,"abstract":"<div><div>The Cybersecurity Internal Audit Framework (CIAF) for the European Space Agency’s Navigation Satellite Systems addresses the growing complexity and criticality of cybersecurity in space navigation. Focusing on ESA’s navigation programs, the framework integrates risk assessment, compliance analysis, and software development process standards into a multi-level audit methodology. By referencing leading international standards and applying a structured approach across ESA, prime contractors, and subcontractors, the CIAF supports continuous improvement, regulatory compliance, and the resilience of Europe’s navigation infrastructure. Its effectiveness is demonstrated through application within ESA’s GNSS programs. Overall, the paper highlights a novel ESA cybersecurity auditing framework that integrates international standards and supply chain analysis, enabling risk monitoring and mitigation in the navigation domain since 2019.</div></div>","PeriodicalId":37283,"journal":{"name":"Journal of Space Safety Engineering","volume":"13 2","pages":"Pages 448-461"},"PeriodicalIF":1.8000,"publicationDate":"2026-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Space Safety Engineering","FirstCategoryId":"1085","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2468896726000443","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"2026/4/1 0:00:00","PubModel":"Epub","JCR":"Q3","JCRName":"ENGINEERING, AEROSPACE","Score":null,"Total":0}
引用次数: 0
Abstract
The Cybersecurity Internal Audit Framework (CIAF) for the European Space Agency’s Navigation Satellite Systems addresses the growing complexity and criticality of cybersecurity in space navigation. Focusing on ESA’s navigation programs, the framework integrates risk assessment, compliance analysis, and software development process standards into a multi-level audit methodology. By referencing leading international standards and applying a structured approach across ESA, prime contractors, and subcontractors, the CIAF supports continuous improvement, regulatory compliance, and the resilience of Europe’s navigation infrastructure. Its effectiveness is demonstrated through application within ESA’s GNSS programs. Overall, the paper highlights a novel ESA cybersecurity auditing framework that integrates international standards and supply chain analysis, enabling risk monitoring and mitigation in the navigation domain since 2019.