Publication: enisa-stl-2025-03 Space Threat Landscape
Full text
The control text is third-party content; see the official source for the full wording.
Mapped SPARTA techniques
19 techniques
A documented secure development lifecycle is relevant to integration review, but the generic secure-engineering-principles excerpt does not actively prevent the multi-component collusion DE-0012 designs to appear benign in isolation.
A documented secure development lifecycle governs engineering practice and is relevant to code integrity, but the generic secure-engineering-principles excerpt does not actively prevent a deliberately inserted geofence-conditional implant, which is not a defect class secure coding removes.
A documented secure development lifecycle is relevant to code quality, but the generic secure-engineering-principles excerpt does not actively prevent the runtime authentication-process modification EX-0003 uses (hot-patching, handler hooking, MAC short-circuiting).
A documented secure development lifecycle is the engineering discipline through which design flaws (test modes, debug straps, MMU corner cases) are identified and removed.
A documented secure development lifecycle is relevant to reviewing code paths that consume trusted time, but the generic secure-engineering-principles excerpt does not actively prevent the deliberately inserted absolute-time trigger EX-0008.01 uses.
A documented secure development lifecycle is the operator-side discipline against the software defects EX-0009 abuses for arbitrary code execution.
A documented secure development lifecycle is the engineering discipline against the unchecked-length, overflow, race, and state-cleanup defects EX-0009.01 exploits in flight software.
Secure development lifecycle principles cover OS configuration hardening, removal of management consoles in flight builds, and least-privilege syscall wrappers.
A secure development lifecycle governs secure engineering principles that reduce the writable-executable and table-driven seams EX-0010 abuses, relevant to the technique at the governance level rather than actively blocking injection at runtime.
A documented secure development lifecycle is relevant to code quality, but the generic secure-engineering-principles excerpt does not name constant-time or timing-safe coding and so does not actively prevent the timing side-channel EXF-0002.04 exploits.
Secure development lifecycle principles cover the engineering controls that detect embedded telemetry taps and extended logging in test harnesses and flight builds.
A documented secure development lifecycle establishes the engineering principles that govern dependency selection, build runners, and import controls.
A documented secure development lifecycle covers separation-kernel and hypervisor design including IOMMU-bounded driver backends and hardened message-port services.
A secure development lifecycle governs secure engineering principles relevant to reducing backdoor insertion during development, at the governance level rather than actively detecting an introduced backdoor.
Secure development lifecycle principles surface intentionally crafted hidden command handlers and special user/role constructs during code review.
A documented secure development lifecycle is the discipline through which flight and ground software details (RTOS choice, FDIR logic, debug hooks) are protected from disclosure.
A documented secure development lifecycle is the operator-side discipline that protects the FSW dev environment, CI/CD, and toolchains from intelligence collection.
A secure development lifecycle is the umbrella discipline whose engineering principles guard the development environment.
The secure development lifecycle governs how security testing tools and their outputs are stored, accessed, and disposed of.