All ENISA publications
ENISA-STL-2025-03-sD.21-i03

Publication: enisa-stl-2025-03 Space Threat Landscape

Full text

The control text is third-party content; see the official source for the full wording.

Mapped SPARTA techniques

19 techniques

  • DE-0012Component CollusionST0006
    addresses
    moderate

    A documented secure development lifecycle is relevant to integration review, but the generic secure-engineering-principles excerpt does not actively prevent the multi-component collusion DE-0012 designs to appear benign in isolation.

  • A documented secure development lifecycle governs engineering practice and is relevant to code integrity, but the generic secure-engineering-principles excerpt does not actively prevent a deliberately inserted geofence-conditional implant, which is not a defect class secure coding removes.

  • A documented secure development lifecycle is relevant to code quality, but the generic secure-engineering-principles excerpt does not actively prevent the runtime authentication-process modification EX-0003 uses (hot-patching, handler hooking, MAC short-circuiting).

  • EX-0005.01Design FlawsST0004
    addresses
    high

    A documented secure development lifecycle is the engineering discipline through which design flaws (test modes, debug straps, MMU corner cases) are identified and removed.

  • EX-0008.01Absolute Time SequencesST0004
    addresses
    moderate

    A documented secure development lifecycle is relevant to reviewing code paths that consume trusted time, but the generic secure-engineering-principles excerpt does not actively prevent the deliberately inserted absolute-time trigger EX-0008.01 uses.

  • EX-0009Exploit Code FlawsST0004
    addresses
    high

    A documented secure development lifecycle is the operator-side discipline against the software defects EX-0009 abuses for arbitrary code execution.

  • EX-0009.01Flight SoftwareST0004
    addresses
    high

    A documented secure development lifecycle is the engineering discipline against the unchecked-length, overflow, race, and state-cleanup defects EX-0009.01 exploits in flight software.

  • EX-0009.02Operating SystemST0004
    addresses
    moderate

    Secure development lifecycle principles cover OS configuration hardening, removal of management consoles in flight builds, and least-privilege syscall wrappers.

  • EX-0010Malicious CodeST0004
    addresses
    moderate

    A secure development lifecycle governs secure engineering principles that reduce the writable-executable and table-driven seams EX-0010 abuses, relevant to the technique at the governance level rather than actively blocking injection at runtime.

  • EXF-0002.04Timing AttacksST0008
    addresses
    moderate

    A documented secure development lifecycle is relevant to code quality, but the generic secure-engineering-principles excerpt does not name constant-time or timing-safe coding and so does not actively prevent the timing side-channel EXF-0002.04 exploits.

  • Secure development lifecycle principles cover the engineering controls that detect embedded telemetry taps and extended logging in test harnesses and flight builds.

  • A documented secure development lifecycle establishes the engineering principles that govern dependency selection, build runners, and import controls.

  • LM-0005Virtualization EscapeST0007
    addresses
    moderate

    A documented secure development lifecycle covers separation-kernel and hypervisor design including IOMMU-bounded driver backends and hardened message-port services.

  • PER-0002BackdoorST0005
    addresses
    moderate

    A secure development lifecycle governs secure engineering principles relevant to reducing backdoor insertion during development, at the governance level rather than actively detecting an introduced backdoor.

  • PER-0002.02Software BackdoorST0005
    addresses
    moderate

    Secure development lifecycle principles surface intentionally crafted hidden command handlers and special user/role constructs during code review.

  • REC-0001.01Software DesignST0001
    addresses
    moderate

    A documented secure development lifecycle is the discipline through which flight and ground software details (RTOS choice, FDIR logic, debug hooks) are protected from disclosure.

  • A documented secure development lifecycle is the operator-side discipline that protects the FSW dev environment, CI/CD, and toolchains from intelligence collection.

  • REC-0006.01Development EnvironmentST0001
    addresses
    moderate

    A secure development lifecycle is the umbrella discipline whose engineering principles guard the development environment.

  • REC-0006.02Security Testing ToolsST0001
    addresses
    moderate

    The secure development lifecycle governs how security testing tools and their outputs are stored, accessed, and disposed of.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.