All ENISA publications
ENISA-STL-2025-03-sD.23-i11

Publication: enisa-stl-2025-03 Space Threat Landscape

Full text

The control text is third-party content; see the official source for the full wording.

Mapped SPARTA techniques

26 techniques

  • Cryptography and key management mandates that the spacecraft cannot disable cryptography on TT&C — directly defeating crypto-mode obfuscation that selects 'crypto off' or null cipher profiles.

  • DE-0004MasqueradingST0006
    addresses
    high

    Cryptography and key management denies the keys needed to forge cryptographically-authenticated traffic, but DE-0004 masquerades across multiple layers: RF-fingerprint imitation (Doppler, polarization, timing, and framing), insider-derived credentials that already pass authentication, and metadata or identifier spoofing for false attribution. Crypto interdicts one vector, not the dominant multi-layer masquerade scope, so the relationship is addresses.

  • EX-0001ReplayST0004
    mitigates
    high

    Cryptography and key management — counter rotation, anti-replay windows, and authenticated encryption — denies replayed traffic acceptance.

  • EX-0001.01Command PacketsST0004
    mitigates
    high

    Cryptography and key management — anti-replay counters and key rotation — turns previously-captured commands into stale, unaccepted traffic.

  • EX-0001.02Bus Traffic ReplayST0004
    addresses
    moderate

    Bus-level authenticated encryption raises the cost of bus replay but does not interdict EX-0001.02's dominant scope. Many bus subsystems act on the latest message or on message rate rather than on uniqueness, and time-triggered buses resist anti-replay, so replayed well-formed frames can still drive resource exhaustion and determinism abuse. Cryptography and key management is in-domain but is not the operative interdiction of this technique, so at the Cryptography and Crypto Key Management control the relationship is addresses, not mitigates.

  • Cryptography and key management mandates that the spacecraft cannot disable cryptography on the TT&C link (no crypto-bypass mode), the named defense against EX-0006.

  • EXF-0001ReplayST0008
    addresses
    high

    Cryptography and key management governs the cryptographic foundation relevant to replay defense, but the generic rules excerpt does not itself provide the active anti-replay mechanism.

  • EXF-0002.04Timing AttacksST0008
    addresses
    moderate

    Use of only approved cryptographic algorithms governs the cryptographic domain that timing attacks (EXF-0002.04) target; the excerpt does not itself assert constant-time/timing-resistant implementation, so the relationship is relevance-level.

  • EXF-0003Signal InterceptionST0008
    addresses
    high

    Cryptography and key management with authenticated encryption renders intercepted bitstreams as ciphertext to the adversary.

  • Cryptography and key management on uplink command sessions with anti-replay counters renders intercepted uplink content non-readable and time-stale.

  • Cryptography and key management mandates uplink/downlink encryption to prevent eavesdropping; unprotected downlink content is the precise EXF-0003.02 target.

  • IA-0001.02Software Supply ChainST0003
    addresses
    moderate

    Cryptography and key management for code-signing keys denies the stolen-signing-key vector, but IA-0001.02's dominant scope is supply-chain manipulation across the pipeline: altering source before build, version rollback to re-introduce known weaknesses, and update-metadata subversion, all of which yield artifacts that are then legitimately signed. Crypto covers one non-dominant vector, so the relationship is addresses.

  • Cryptography and key management explicitly mandates ISL encryption — the named defense against compromised-neighbor crosslink injection.

  • IA-0004.02ReceiverST0003
    addresses
    moderate

    Cryptography on uplink/downlink is relevant to protecting the backup receive path, but the eavesdropping-prevention excerpt does not actively defend against command exploitation of the backup receiver.

  • IA-0005.01Compromise EmanationsST0003
    addresses
    moderate

    Key-update-frequency and key-length governance is relevant to limiting the value of keys exposed via emanations, but does not actively defend against the side-channel extraction itself.

  • Cryptography and key management on signing keys denies forging an update package without the key, but IA-0007.01's dominant scope is pre-signing pipeline compromise: substituting or modifying artifacts at source repositories, build and packaging steps, and staging areas, which are then signed and promoted through normal procedures. Crypto does not reach the dominant pre-signing scope, so the relationship is addresses.

  • Cryptography and key management restricts encryption keys to authorised endpoints, so a rogue ground station cannot issue accepted commands without compromised keys.

  • Cryptography and key management explicitly mandates ISL encryption — the canonical defence against constellation-hopping via crosslink.

  • Cryptography and key management governs the uplink-key lifecycle (handling outside on-board software, key restrictions, rotation cadence, anomaly review) that PER-0004 attempts to subvert.

  • RD-0001.01Ground Station EquipmentST0002
    addresses
    moderate

    Cryptography and key management denies adversary-built ground equipment the keys to issue accepted commands, but RD-0001.01's defining act is the acquisition and assembly of an RF ground stack, which crypto does not interdict; the equipment retains passive-collection and active-probing utility. Crypto blunts the downstream commanding use rather than the technique's defining vector, so the relationship is addresses.

  • RD-0003.02Cryptographic KeysST0002
    addresses
    high

    Cryptography and key management interdicts a partial set of RD-0003.02's key-acquisition routes (onboard key handling and the telecommand-read restriction) and limits the lifetime of obtained keys through rotation, but the dominant acquisition routes are ground-side and non-crypto: compromised ground systems and laptops, misconfigured repositories, memory and core dumps, and contractor or human channels. Crypto covers the minority of routes, so the relationship is addresses.

  • Cryptography and key management directly governs the algorithms, key types, lifecycles, counters, and anti-replay rules that REC-0001.03 attempts to enumerate.

  • Cryptography and key management governs the authentication scheme (keys, counters, anti-replay windows) REC-0003.02 studies and reduces the value of what is learned, but it does not actively prevent the reconnaissance itself, so addresses rather than mitigates.

  • REC-0003.04Valid CredentialsST0001
    addresses
    high

    Cryptography and key management protects TT&C keys, link-encryption keys, and counters — exactly the credential families REC-0003.04 targets in space and ground.

  • REC-0005EavesdroppingST0001
    mitigates
    high

    Cryptography and key management provides the encryption that turns wideband recordings into ciphertext for the eavesdropping adversary.

  • Encryption on the uplink/downlink to prevent eavesdropping is mandated under cryptography and key management.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.