Loss of Availability
Description
Adversaries may attempt to disrupt essential components or systems to prevent owner and operator from delivering products or services. (Citation: Corero) (Citation: Michael J. Assante and Robert M. Lee) (Citation: Tyson Macaulay) Adversaries may leverage malware to delete or encrypt critical data on HMIs, workstations, or databases. In the 2021 Colonial Pipeline ransomware incident, pipeline operations were temporally halted on May 7th and were not fully restarted until May 12th. (Citation: Colonial Pipeline Company May 2021)
Mapped SPARTA techniques
2 techniques
T0826 'Loss of Availability' addresses adversary actions causing unavailability of system/process resources; ransomware encrypts data to deny availability — same impact concept. Cross-tactic moderate (impact vs execution) and concept-adjacent (ICS has no specific ransomware technique; T0826 captures the availability-denial outcome).
T0826 'Loss of Availability' is in MITRE ICS impact tactic and addresses adversary actions causing unavailability of system/process resources; SPARTA IMP-0003 'Denial' (deny access entirely) is the parent-level spacecraft equivalent. Tactic and activity align directly; T0826 is the broadest availability-loss impact technique applicable.
Cite as SafeMode Space, mitre-attack-ics T0826.