Publication: enisa-stl-2025-03 Space Threat Landscape
Full text
The control text is third-party content; see the official source for the full wording.
Mapped SPARTA techniques
21 techniques
Third-party risk management covers SDA partners whose compromised feeds DE-0009.05 spoofs or saturates.
Cyber supply-chain risk management with multi-supplier diversification reduces the surface where coordinated-component compromise can stage cooperative behaviour.
Cyber supply-chain risk management of partners — commercial ground stations, relay networks, ops service providers, data processing partners — is the named control governing EXF-0009 vectors.
Third-party risk management governs the payload-operator and customer-network agreements through which EXF-0010 routes host-bus content.
Cyber supply chain risk management explicitly covers third-party suppliers whose compromise enables IA-0001.
Third-party risk management is the operator-side discipline that vets the servicer organisation whose vehicle docks via this technique.
Third-party risk management governs hosted-payload operator agreements where keying, procedures, and scheduling differ between payload and bus operator.
Cyber supply-chain risk management of partners, vendors, and user communities is the named operator-side discipline that scopes the trust relationships IA-0009 abuses.
Third-party risk management explicitly covers science operations centers, instrument builders, and international partners in the SCRM scope.
Multi-supplier strategies and cyber-SCRM processes reduce single-vendor dependency that enables the IA-0009.02 footprint.
Third-party risk management governs vendor support accounts and transient assets active during ATLO that move software between staging and flight hardware.
Third-party risk management between host operator and payload operator is the agreement-side discipline that constrains the IA-0013 vector.
Third-party risk management covers hosted-payload operator agreements where command dictionaries and gateway services differ between payload and host.
Third-party risk management vets the visiting-vehicle operator whose docking introduces high-trust connections.
Third-party risk management covers launch providers and integrators whose cross-organisation responsibilities create the heterogeneity LM-0006 exploits.
Third-party risk management covers co-payload operators whose mispartitioned domains create LM-0006.01's transit pathway.
Third-party risk management on commercial ground station providers is the operator-side discipline that vets and audits the very providers an adversary might rent through.
Third-party risk management is the operator-side discipline through which 3rd-party ground systems providing mission services are assessed and monitored.
Third-party risk management explicitly covers other operators whose spacecraft share infrastructure with the host mission.
Third-party risk management explicitly covers component and equipment suppliers — the targets of hardware-supply-chain reconnaissance.
Third-party risk management governs how supplier and partner relationships are assessed, the same relationships REC-0008.04 enumerates.