Formal methods can complement traditional techniques such as testing and can help developers improve the degree of trustworthiness in defense acquisitions. In this paper, we demonstrate an application of formal methods to a system-of-systems development by specifying and verifying part of the controlling software for a ballistic missile defense system. While there is much work to do to institutionalize formal methods in the development of system-of-systems, we believe that this paper represents a point of departure towards that objective.