All ENISA publications
ENISA-STL-2025-03-sD.20-i04

Publication: enisa-stl-2025-03 Space Threat Landscape

Full text

The control text is third-party content; see the official source for the full wording.

Mapped SPARTA techniques

21 techniques

  • Third-party risk management covers SDA partners whose compromised feeds DE-0009.05 spoofs or saturates.

  • DE-0012Component CollusionST0006
    addresses
    high

    Cyber supply-chain risk management with multi-supplier diversification reduces the surface where coordinated-component compromise can stage cooperative behaviour.

  • EXF-0009Compromised Partner SiteST0008
    addresses
    moderate

    Cyber supply-chain risk management of partners — commercial ground stations, relay networks, ops service providers, data processing partners — is the named control governing EXF-0009 vectors.

  • Third-party risk management governs the payload-operator and customer-network agreements through which EXF-0010 routes host-bus content.

  • IA-0001Compromise Supply ChainST0003
    addresses
    moderate

    Cyber supply chain risk management explicitly covers third-party suppliers whose compromise enables IA-0001.

  • Third-party risk management is the operator-side discipline that vets the servicer organisation whose vehicle docks via this technique.

  • Third-party risk management governs hosted-payload operator agreements where keying, procedures, and scheduling differ between payload and bus operator.

  • IA-0009Trusted RelationshipST0003
    addresses
    high

    Cyber supply-chain risk management of partners, vendors, and user communities is the named operator-side discipline that scopes the trust relationships IA-0009 abuses.

  • Third-party risk management explicitly covers science operations centers, instrument builders, and international partners in the SCRM scope.

  • IA-0009.02VendorST0003
    addresses
    moderate

    Multi-supplier strategies and cyber-SCRM processes reduce single-vendor dependency that enables the IA-0009.02 footprint.

  • Third-party risk management governs vendor support accounts and transient assets active during ATLO that move software between staging and flight hardware.

  • IA-0013Compromise Host SpacecraftST0003
    addresses
    moderate

    Third-party risk management between host operator and payload operator is the agreement-side discipline that constrains the IA-0013 vector.

  • LM-0001Hosted PayloadST0007
    addresses
    moderate

    Third-party risk management covers hosted-payload operator agreements where command dictionaries and gateway services differ between payload and host.

  • Third-party risk management vets the visiting-vehicle operator whose docking introduces high-trust connections.

  • LM-0006Launch Vehicle InterfaceST0007
    addresses
    moderate

    Third-party risk management covers launch providers and integrators whose cross-organisation responsibilities create the heterogeneity LM-0006 exploits.

  • LM-0006.01Rideshare PayloadST0007
    addresses
    high

    Third-party risk management covers co-payload operators whose mispartitioned domains create LM-0006.01's transit pathway.

  • Third-party risk management on commercial ground station providers is the operator-side discipline that vets and audits the very providers an adversary might rent through.

  • Third-party risk management is the operator-side discipline through which 3rd-party ground systems providing mission services are assessed and monitored.

  • Third-party risk management explicitly covers other operators whose spacecraft share infrastructure with the host mission.

  • REC-0008.01Hardware ReconST0001
    addresses
    moderate

    Third-party risk management explicitly covers component and equipment suppliers — the targets of hardware-supply-chain reconnaissance.

  • REC-0008.04Business RelationshipsST0001
    addresses
    moderate

    Third-party risk management governs how supplier and partner relationships are assessed, the same relationships REC-0008.04 enumerates.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.