Publication: enisa-stl-2025-03 Space Threat Landscape
Full text
The control text is third-party content; see the official source for the full wording.
Mapped SPARTA techniques
15 techniques
Supplier security management with ISMS audits scopes the supply-chain relationships under which component-collusion compromise must arise.
Supplier security management requires evidence of security posture from third-party stations and providers whose feed-mirroring or scraping enables EXF-0009.
Supplier security management is the umbrella supply-chain control governing the manufacturing, integration, and delivery contexts where IA-0001 inserts code or hardware.
Supplier security management requires evidence of security posture from board, module, and programmable-logic suppliers, the route IA-0001.03 exploits.
Supplier security management requires evidence of security posture from the third parties whose compromise enables the IA-0009 inheritance pattern.
Supplier security management with ISMS audits and reviews directly addresses vendor compromise as the IA-0009.02 vector.
Supplier security management on host-spacecraft providers establishes the audit baseline limiting host-side compromise propagation into hosted payloads.
Supplier security management requires evidence of security posture from launch-vehicle providers and EGSE operators.
Supplier security management governs the contractual and audit posture of the legitimate-infrastructure providers an adversary attempts to compromise.
Supplier security management requires 3rd-party ground system operators to demonstrate security management posture before entering the mission's commanding pathway.
Supplier security management on co-hosted spacecraft providers establishes the audit and standards baseline that limits compromise propagation.
Supplier security management covers launch providers, integrators, range operators, and telemetry network providers whose pre-launch staff REC-0004 profiles.
Supplier security management is the umbrella supply-chain control that governs whose disclosures REC-0008 can mine.
Supplier security management governs the hardware vendor ecosystem whose security practices REC-0008.01 reconnoitres.
Supplier security management documents and audits the contractual security relationships REC-0008.04 maps for leverage.