Publication: enisa-stl-2025-03 Space Threat Landscape
Full text
The control text is third-party content; see the official source for the full wording.
Mapped SPARTA techniques
5 techniques
Incident response procedures including SIEM-driven alerting cover detection of compromised telemetry processing.
Incident response procedures define the recovery path when a ground-system foothold is detected, with SIEM-driven log centralisation and trigger alerts.
Incident response procedures including SIEM-driven correlation across signals reduce the time deception goes undetected and the effect of false TTPs.
A documented incident response plan governs the procedures for responding to disruption events, relevant to shortening their duration rather than actively preventing the disruption.
A documented incident response plan governs procedures for responding to ground-system presence, relevant to shortening dwell time rather than actively preventing the persistence.