cra

Annex I, Part I, (2)(d)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (65)

Techniques referencing this article

  • DE-0003.03Command Receiver On/Off ModeST0006
    mitigates
    moderate
    direct

    Receiver-enable changes should require authenticated configuration commands and access controls; (2)(d)'s authentication and access-management obligation mitigates this attack at the config-change boundary.

  • DE-0003.07Cryptographic ModesST0006
    addresses
    high
    direct

    Crypto-mode manipulation including authentication-bypass selection (e.g., turning to a profile the ground does not validate against) is the precise attack (2)(d)'s authentication obligation requires the product to resist.

  • DE-0004MasqueradingST0006
    addresses
    high
    direct

    Masquerading by crafting authenticated-looking telecommand frames, imitating station fingerprints, or replaying crosslink identities is the canonical authentication-bypass attack (2)(d) requires the product's access-management mechanisms to resist.

  • DE-0005Subvert Protections via Safe-ModeST0006
    addresses
    moderate
    direct

    Issuing maintenance-looking commands under safe-mode's broadened acceptance is an authentication-bypass scenario (2)(d) requires the product's access-management to resist regardless of operating mode.

  • Intermittent or misleading transponder replies and spoofed RF identities are authentication failures of the proximity-identification protocol — within (2)(d)'s authentication and report-on-unauthorised-access scope.

  • DE-0011Credentialed EvasionST0006
    addresses
    high
    direct

    Credentialed evasion is the canonical case (2)(d)'s 'report on possible unauthorised access' clause is meant to surface — appropriate-control-mechanisms must include detection of legitimate-but-anomalous credential use.

  • EX-0001ReplayST0004
    mitigates
    moderate
    derived

    Manufacturer authentication obligations include replay-resistant mechanisms (counters, timestamps, MAC binding); products designed under (2)(d) reject re-sent traffic and convert replay attempts into immediate rejection.

  • EX-0001.01Command PacketsST0004
    mitigates
    high
    derived

    Telecommand authentication with monotonic counters and MAC binding makes whole-PDU replay unsuccessful; this is the manufacturer-side defense against captured-and-replayed commands.

  • EX-0001.02Bus Traffic ReplayST0004
    addresses
    high
    derived

    Authentication on internal command/data buses (1553, SpaceWire, custom) is the manufacturer-side control that resists bus-traffic replay; products should enforce origin authentication on bus messages.

  • EX-0003Modify Authentication ProcessST0004
    addresses
    moderate
    derived

    Authentication architecture itself is an obligation; manufacturers must design auth processes that resist self-modification through hardware-rooted identity and signed/enforced code paths.

  • EX-0004Compromise Boot MemoryST0004
    addresses
    moderate
    derived

    Authentication of boot artefacts (signed bootloaders, hardware root of trust) is a manufacturer-side protection mechanism encompassed by (2)(d) access-control obligations.

  • Manufacturer obligation to provide protection from unauthorized access via authentication and access-management applies to low-level/maintenance command interfaces; products must constrain JTAG, scan-chain and memory-mapped-register access.

  • EX-0006Disable/Bypass EncryptionST0004
    addresses
    moderate
    derived

    Authentication and access-control obligations bound who can issue commands that toggle cryptographic state, narrowing the population that can subvert encryption.

  • Authentication obligations apply during safe-mode; manufacturer-designed safe-mode profiles must not relax auth requirements that would otherwise be enforced.

  • EX-0012Modify On-Board ValuesST0004
    addresses
    high
    derived

    Authentication and access-management obligations bound which actors can write to live or persistent on-board values.

  • EX-0012.01RegistersST0004
    addresses
    high
    derived

    Authentication-and-access-control obligations apply to register-level interfaces; manufacturers must constrain which actors can issue memory-mapped register writes.

  • EX-0012.03Memory Write/LoadsST0004
    addresses
    high
    derived

    Authentication obligations bound who can issue raw memory operations; manufacturers must constrain memory-write authority via factor-bound auth.

  • EX-0012.05Scheduling AlgorithmST0004
    addresses
    moderate
    derived

    Authentication obligations bound who can alter scheduling parameters whose modification can starve safety-critical tasks.

  • EX-0012.07Propulsion SubsystemST0004
    addresses
    high
    derived

    Authentication obligations bound who can alter propulsion parameters whose tampering produces mission-impact effects.

  • Authentication bounds who can issue ADCS-parameter modifications.

  • EX-0012.10Command & Data Handling SubsystemST0004
    addresses
    moderate
    derived

    Authentication bounds who can alter C&DH configuration that governs command parsing and dispatch.

  • EX-0013.01Valid CommandsST0004
    addresses
    moderate
    derived

    Authentication procedures with rate-limiting, per-counter validation and identity binding reduce the resource cost of valid-command flooding by enabling cheap rejection.

  • EX-0014SpoofingST0004
    addresses
    high
    derived

    Authentication obligations bind inputs to verifiable identities; spoofed inputs lacking valid authentication tokens are rejected by subsystems applying these procedures.

  • EX-0014.01Time SpoofST0004
    addresses
    moderate
    derived

    Authentication on time-distribution paths (signed PTP/NTP, authenticated cross-link time tags) reduces the success of forged time inputs.

  • EX-0014.02Bus Traffic SpoofingST0004
    addresses
    high
    derived

    Authentication on internal bus interfaces (1553, SpaceWire, custom) is the manufacturer-side defense against forged-frame injection from arbitrary nodes.

  • EXF-0001ReplayST0008
    addresses
    high
    direct

    Replay-resistant authentication (counter freshness, nonces, timestamp windows) is the precise authentication property (2)(d) requires the product's access-management mechanisms to provide.

  • EXF-0003Signal InterceptionST0008
    addresses
    moderate
    inferred

    Authentication and access-management (2)(d) addresses EXF-0003 by limiting reuse of intercepted commands via replay-counter binding, but the interception vector itself is interdicted by confidentiality/encryption (2)(e); recorded here as addresses.

  • EXF-0003.01Uplink ExfiltrationST0008
    addresses
    moderate
    inferred

    Authentication with replay protection (2)(d) addresses EXF-0003.01 by reducing reuse of captured uplink material, but interception of the command path is interdicted by confidentiality/encryption (2)(e); recorded here as addresses.

  • EXF-0003.02Downlink ExfiltrationST0008
    addresses
    moderate
    inferred

    Art. (2)(d) is access-control relevant (authenticated frame structure limits reuse/replay of captured material) but does not interdict the eavesdropping vector itself; the operative control against interception of downlink content is confidentiality/encryption (2)(e).

  • EXF-0004Out-of-Band Communications LinkST0008
    addresses
    moderate
    direct

    Out-of-band channels need the same authentication and access-management discipline as primary TT&C; (2)(d)'s appropriate-control-mechanisms obligation covers vendor/service modes that carry file fragments.

  • EXF-0006Modify Communications ConfigurationST0008
    mitigates
    moderate
    direct

    Communications-config changes should require authenticated commands and access controls; (2)(d)'s authentication and access-management obligation mitigates this attack at the config-change boundary.

  • EXF-0006.01Software Defined RadioST0008
    addresses
    moderate
    direct

    SDR profile/configuration changes should require authenticated commands; (2)(d)'s authentication obligation applies to all privileged configuration interfaces.

  • EXF-0006.02TransponderST0008
    addresses
    moderate
    direct

    Transponder routing/QoS changes should require authenticated commands; (2)(d)'s access-management obligation governs who can edit these tables.

  • EXF-0007Compromised Ground SystemST0008
    addresses
    high
    direct

    Compromise of operator workstations, mission control servers, and telemetry processing pipelines is the canonical case (2)(d)'s authentication and access-management obligation addresses for ground-segment products with digital elements.

  • EXF-0009Compromised Partner SiteST0008
    addresses
    moderate
    direct

    Cross-organization links (partner stations to MOC) need authenticated boundary controls; (2)(d)'s access-management obligation mitigates man-in-the-middle on these links when paired with mutual authentication.

  • Manufacturer obligation to provide authentication and access-management mechanisms applies to crosslink interfaces; properly-authenticated peers preclude a compromised neighbor from being a bridgehead.

  • Manufacturer authentication obligations apply uniformly to primary and secondary/backup channels; the product must enforce equivalent authentication on contingency TT&C, beacons and emergency commanding paths.

  • IA-0004.01Ground StationST0003
    addresses
    high
    derived

    Authentication obligations apply equally on backup ground-station infrastructure; products must enforce equivalent auth on contingency commanding paths.

  • IA-0004.02ReceiverST0003
    addresses
    high
    derived

    Backup on-board receivers must enforce the same authentication mechanisms as the primary path under the manufacturer's product-cybersecurity obligations.

  • IA-0005.02Docked Vehicle / OSAMST0003
    addresses
    moderate
    derived

    Authentication obligations apply to docking/berthing interfaces; the product must enforce mutual authentication on rendezvous-permission, capture-permission and post-dock command exchanges.

  • IA-0006Compromise Hosted PayloadST0003
    addresses
    moderate
    derived

    Authentication obligations apply to payload-to-bus command interfaces; the bus should accept payload-originating commands only with manufacturer-defined authentication.

  • IA-0007Compromise Ground SystemST0003
    addresses
    high
    derived

    Authentication obligations apply to ground-system products that command the spacecraft; mission-control software, baseband modems and operator workstation tooling must enforce manufacturer-defined authentication.

  • Manufacturer authentication obligations require strong, factor-based identity verification on commanding consoles; valid-GS misuse (using already-configured ground equipment) is bounded when the product enforces independent multi-factor authentication on commanding actions.

  • IA-0008Rogue External EntityST0003
    mitigates
    moderate
    derived

    Authentication obligations on the spacecraft uplink (cryptographic command authentication, counters, replay protection) reduce a rogue external transmitter to noise; the product manufacturer must implement these mechanisms regardless of the legitimate ground architecture.

  • IA-0008.01Rogue Ground StationST0003
    mitigates
    high
    derived

    Manufacturer-implemented authentication on the uplink defeats rogue ground stations: per-counter MAC verification rejects commands lacking valid keys regardless of transmit power or geometry.

  • IA-0008.02Rogue SpacecraftST0003
    mitigates
    moderate
    derived

    Authentication on crosslink and proximity-domain interfaces converts a rogue spacecraft into an unauthenticated peer; manufacturer-mandated auth makes RF geometry insufficient without valid keys.

  • IA-0009Trusted RelationshipST0003
    addresses
    moderate
    derived

    Authentication obligations bound the privileges third-party connections receive within the product; products designed under (2)(d) require explicit, factor-bound auth even from trusted relationships.

  • IA-0009.02VendorST0003
    addresses
    high
    derived

    Authentication obligations bound vendor remote-administration access; manufacturer-enforced auth on these privileged paths prevents credential leak from converting into operations-affecting access.

  • IA-0009.03User SegmentST0003
    addresses
    moderate
    derived

    Authentication on user-segment interfaces bounds what user-segment compromise can reach in the product's commanding or telemetry-distribution backends.

  • Authentication obligations apply during safe-mode; manufacturer-designed safe-mode profiles must not relax auth requirements that would otherwise be enforced.

  • IA-0011Auxiliary Device CompromiseST0003
    addresses
    moderate
    derived

    Authentication on peripheral interfaces bounds which auxiliary devices can deliver data or code to the product.

  • IMP-0001Deception (or Misdirection)ST0009
    addresses
    moderate
    direct

    Compromised allied ground infrastructure used as the source of communications to the spacecraft is an authentication-bypass scenario (2)(d) requires the spacecraft's access-management to resist regardless of source apparent legitimacy.

  • IMP-0006TheftST0009
    addresses
    moderate
    direct

    Strict authentication and access-management mechanisms restrict who can access the data stores and downlink channels theft would target — within (2)(d)'s appropriate-control-mechanisms scope.

  • LM-0001Hosted PayloadST0007
    addresses
    moderate
    direct

    Authentication and access-management mechanisms across the gateway processor between host and payload mitigate the privileged-service requests (time/ephemeris distribution, firmware loads) that LM-0001 abuses.

  • LM-0002Exploit Lack of Bus SegregationST0007
    mitigates
    moderate
    direct

    Forging message IDs or terminal addresses, replaying actuator/sensor frames, and seizing bus-controller roles are authentication failures of the bus protocol — within (2)(d)'s authentication and access-management obligation.

  • Crafted crosslink traffic that 'appears to originate from a trusted neighbor' is the canonical authentication-bypass scenario (2)(d) requires the product's access-management to resist on inter-satellite links.

  • LM-0004Visiting Vehicle Interface(s)ST0007
    addresses
    high
    direct

    Docking-time umbilical and firmware push channels are exactly the high-trust access path (2)(d)'s authentication and access-management obligation must scope, even within expected post-dock procedures.

  • LM-0006Launch Vehicle InterfaceST0007
    addresses
    high
    direct

    Launch vehicle ↔ payload commissioning links carry commands, file transfers, and configuration; (2)(d)'s authentication obligation applies to these high-trust short-duration interfaces.

  • LM-0007Credentialed TraversalST0007
    addresses
    high
    direct

    Reuse of credentials/keys to cross domain boundaries is the canonical case (2)(d)'s access-management obligation addresses — appropriate-control-mechanisms must enforce role and scope boundaries on credentials.

  • PER-0003Ground System PresenceST0005
    addresses
    high
    derived

    Authentication and access-management obligations on ground-system products are what bound the convertibility of foothold to commanding access; manufacturer-implemented MFA and identity-binding break long-dwell credential leverage.

  • PER-0004Replace Cryptographic KeysST0005
    addresses
    high
    derived

    Authentication obligations include identity life-cycle management of cryptographic keys; manufacturers must design products so key replacement requires verified, factor-bound authority.

  • PER-0005Credentialed PersistenceST0005
    addresses
    high
    direct

    Credentialed persistence is the canonical case (2)(d) addresses: the obligation requires authentication and identity/access-management mechanisms plus reporting on possible unauthorised access — which credential lifecycle hygiene, monitoring, and access-revocation directly target.

  • RD-0003.02Cryptographic KeysST0002
    addresses
    high
    derived

    Manufacturer obligation to provide authentication and access-management mechanisms determines the value of obtained cryptographic keys: well-designed products bind keys to product-side verification (counters, factor binding, hardware-backed identity) so adversary-acquired keys do not directly yield operational access.

  • REC-0003.02Commanding DetailsST0001
    addresses
    high
    direct

    Manufacturer obligation to ensure protection from unauthorized access by appropriate control mechanisms (including authentication, identity, access management) is the design-side defense that converts commanding-detail reconnaissance into a still-blocked command path: even full knowledge of the command schema does not yield acceptance without valid authentication.

  • REC-0003.04Valid CredentialsST0001
    addresses
    high
    derived

    Manufacturer obligation to provide authentication, identity and access-management mechanisms is the procedural lever that bounds the value of credential reconnaissance: products designed under (2)(d) bind credentials to verified factors so passive harvesting alone does not yield commanding access.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.