Publication: enisa-stl-2025-03 Space Threat Landscape
Full text
The control text is third-party content; see the official source for the full wording.
Mapped SPARTA techniques
9 techniques
Software supply-chain integrity controls (hash sums, supplier audits) raise the cost of inserting two-or-more cooperating modules through the supply chain.
Software supply-chain integrity through hash sums and supplier audits is the explicit control against insertion at distribution edges and update channels.
Supply-chain integrity controls (hash sums, supplier audits) defeat dependency confusion, typosquatting, and compromised CI/CD runners that IA-0001.01 exploits.
Software supply-chain integrity directly defeats binary swapping, update-metadata subversion, and stolen signing-key abuse on delivered patches.
SDR waveforms, bitstreams, and DSP modules ride the same software supply chain whose integrity is governed here, including update-channel hash verification.
Hash-sum integrity and supplier audits on the update pipeline detect substitution of images, differential patches, and update metadata.
Software supply-chain integrity is relevant to the firmware and supply-chain domain REC-0001.02 targets, but hash-sum tamper-detection does not actively prevent reconnaissance of firmware images and vendor packages, so addresses rather than mitigates.
Software supply chain integrity controls regulate the integrity and visibility of the supplier ecosystem REC-0008 attempts to enumerate.
Supply-chain integrity controls regulate hash-sum verification and auditing — the artefacts that limit how readable the dependency graph is to outsiders.