cra

Annex I, Part I, (2)(e)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (23)

Techniques referencing this article

  • DE-0003.07Cryptographic ModesST0006
    addresses
    high
    direct

    Manipulating cryptographic mode controls — flipping profiles, requesting clear telemetry, rotating key IDs — directly attacks the confidentiality obligation under (2)(e), including its state-of-the-art encryption requirement.

  • EX-0006Disable/Bypass EncryptionST0004
    addresses
    high
    direct

    Manufacturer confidentiality obligation requires data to be encrypted by state-of-the-art mechanisms; designs that allow runtime disabling or downgrade-to-clear of encryption violate (2)(e).

  • EX-0012.06Science/Payload DataST0004
    addresses
    moderate
    derived

    The article requires encrypting stored and processed data such as the raw frames, Level-0 streams, calibration tables, and time tags this technique targets in place on mass memory and onboard, and encryption at rest denies an adversary the readable plaintext needed to make the meaningful biased rewrites the technique relies on. It only addresses the technique because the excerpt mandates confidentiality protection and does not require detecting or rejecting alterations to the data itself.

  • EX-0015Side-Channel AttackST0004
    addresses
    high
    derived

    Confidentiality obligation covers data leaked through physical byproducts of computation (timing, power, EM); manufacturer-side TEMPEST hardening, balanced power and constant-time crypto are how (2)(e) is operationalized against side-channel attacks.

  • EXF-0002Side-Channel ExfiltrationST0008
    addresses
    high
    direct

    Side-channel exfiltration attacks the confidentiality property (2)(e) covers; state-of-the-art mechanisms include not just encryption but constant-time crypto, masked implementations, and shielding — the side-channel-resistance disciplines.

  • EXF-0002.01Power Analysis AttacksST0008
    addresses
    high
    direct

    Power-analysis recovery of key bits defeats the confidentiality (2)(e) requires; the 'state-of-the-art mechanisms' clause directly contemplates DPA/CPA-resistant implementations.

  • EM emanations leaking key schedules and protocol framing defeat (2)(e)'s confidentiality property; state-of-the-art mechanisms include shielding, decorrelation, and constant-power design.

  • EXF-0002.03Traffic Analysis AttacksST0008
    addresses
    moderate
    inferred

    mitigates DOWNGRADE: (2)(e) confidentiality is domain-adjacent but does not interdict traffic-flow/timing analysis, since topology and activity timing leak from transceiver duty-cycle even under encryption; the operative controls are traffic-flow padding and constant-rate transmission, not data confidentiality.

  • EXF-0002.04Timing AttacksST0008
    addresses
    moderate
    direct

    Timing attacks recover secrets through code-path-dependent latency; constant-time cryptographic implementations are part of the 'state of the art mechanisms' (2)(e) requires.

  • EXF-0002.05Thermal Imaging attacksST0008
    addresses
    moderate
    inferred

    (2)(e) confidentiality is in the data-protection domain but does not interdict thermal-emanation extraction; the operative control is physical thermal masking/shielding (TEMPEST), so record as addresses.

  • EXF-0003Signal InterceptionST0008
    addresses
    high
    direct

    Capturing mission traffic in transit — RF, optical, baseband, or ground LAN — directly attacks the confidentiality property (2)(e) requires the product to protect via state-of-the-art encryption of data in transit.

  • EXF-0003.01Uplink ExfiltrationST0008
    addresses
    high
    direct

    Uplink interception captures telecommand frames and table uploads; (2)(e)'s state-of-the-art encryption-in-transit obligation directly addresses confidentiality of command-link content.

  • EXF-0003.02Downlink ExfiltrationST0008
    addresses
    high
    direct

    Downlink interception captures real-time telemetry, recorder playbacks, and payload products; (2)(e)'s state-of-the-art encryption-in-transit obligation directly addresses confidentiality of downlinked content, including the case where uplink is protected but downlink is not.

  • EXF-0005Proximity OperationsST0008
    addresses
    high
    direct

    Proximity TEMPEST/EMSEC collection of near-field RF, optical/IR, and conducted emissions defeats confidentiality (2)(e) requires; the 'state of the art mechanisms, and by using other technical means' clause directly contemplates emanation control as a confidentiality measure.

  • EXF-0007Compromised Ground SystemST0008
    addresses
    high
    direct

    Archive databases, payload product stores, and procedure logs hold mission-critical data at rest; (2)(e)'s 'data at rest' encryption obligation directly applies to these ground-system products.

  • EXF-0009Compromised Partner SiteST0008
    addresses
    moderate
    direct

    End-to-end encryption (rather than relying on partner-segment trust) preserves confidentiality even when a partner's environment is compromised — within (2)(e)'s in-transit confidentiality obligation.

  • EXF-0010Payload Communication ChannelST0008
    addresses
    moderate
    inferred

    (2)(e) confidentiality is the data-protection domain but encryption-at-rest does not interdict an implant that reads plaintext host-bus data and forwards it; recording/monitoring (2)(l) and attack-surface limitation on auxiliary channels (2)(j) interdict the covert conduit, so (2)(e) addresses confidentiality posture.

  • IA-0005.01Compromise EmanationsST0003
    addresses
    moderate
    derived

    Confidentiality protection obligations cover processed data; emanations leak data unintentionally and must be constrained at the product level through TEMPEST-style hardening, balanced power and shielding to satisfy the manufacturer's confidentiality obligation.

  • IMP-0006TheftST0009
    addresses
    high
    direct

    Stealing the data the spacecraft gathers, processes, and sends is the canonical confidentiality breach (2)(e) requires the product to protect against via state-of-the-art encryption at rest and in transit.

  • PER-0004Replace Cryptographic KeysST0005
    addresses
    moderate
    derived

    Confidentiality obligation requires manufacturers to encrypt cryptographic key material at rest and in transit; product-side hardware-backed key storage resists adversary key replacement.

  • RD-0003.02Cryptographic KeysST0002
    addresses
    high
    derived

    Manufacturer obligation to protect confidentiality of stored data covers cryptographic key material as the highest-classification data class; encrypted, hardware-bound key storage on the product is the procedural defense that resists key acquisition.

  • REC-0001.03Cryptographic AlgorithmsST0001
    addresses
    moderate
    derived

    Manufacturers must protect the confidentiality of stored, transmitted or processed data, including by encrypting cryptographic-state data such as keys and counter material; this constrains the leakage of crypto-algorithm and key-lifecycle details that algorithm-reconnaissance targets when it can probe a deployed product.

  • REC-0003.04Valid CredentialsST0001
    addresses
    moderate
    derived

    Confidentiality protection of stored credential material (encrypted key stores, secure tokens, hardware-backed identity) is the manufacturer-side control that resists in-product credential exfiltration during recon.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.