All ENISA publications
ENISA-STL-2025-03-sD.26-i02

Publication: enisa-stl-2025-03 Space Threat Landscape

Full text

The control text is third-party content; see the official source for the full wording.

Mapped SPARTA techniques

16 techniques

  • Least-privilege access control and four-eyes principle on telemetry pipelines and display interfaces denies the foothold needed to disable or falsify telemetry processing.

  • Least-privilege access control on hardware-command interfaces denies the broad device-level reach EX-0005.02 needs.

  • Least-privilege access control on operator workstations, archive databases, and processing pipelines denies the broad reach EXF-0007 needs to siphon data at scale.

  • Least-privilege access control between payload commanding and host-bus data denies the implant the privileges needed to route host content into payload links.

  • IA-0004.01Ground StationST0003
    addresses
    high

    Access control with least privilege and four-eyes principle on the backup MOC and contingency stations defeats the foothold IA-0004.01 establishes there.

  • Least-privilege access control between hosted payload and host-bus management functions denies IA-0006 the cross-strapped pivot it relies on.

  • Least privilege, separation of duties, and four-eyes principle on operator workstations and mission control software directly defeat IA-0007 footholds.

  • Four-eyes principle and separation of duties make insertion of malicious commands into existing timelines visible to a second operator.

  • Least-privilege access control on cross-organization tools and federated credentials limits the reach of a compromised collaborator into mission workflows.

  • Least-privilege access control on EGSE, simulators, and test controllers denies a compromised laptop the broad reach IA-0012 needs.

  • LM-0001Hosted PayloadST0007
    addresses
    moderate

    Least-privilege access control between hosted payload and host-bus management functions denies LM-0001's transit through trusted interfaces.

  • Least-privilege access control with separation of duties denies single-credential traversal across multiple enclaves.

  • Least-privilege access control on operator workstations, schedulers, and station control directly attacks the foothold PER-0003 maintains in mission ground infrastructure.

  • PER-0004Replace Cryptographic KeysST0005
    mitigates
    moderate

    Least-privilege access control with separation of duties and four-eyes principle on rekey procedures denies unilateral key replacement by a compromised operator account.

  • PER-0005Credentialed PersistenceST0005
    addresses
    moderate

    Least-privilege access control with separation of duties limits the reach of any persistently-held credential.

  • Access control with least privilege, separation of duties, and four-eyes principle governs who can access mission-operated ground systems and how, addressing this technique directly.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.