cra

Annex I, Part I, (2)(j)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (29)

Techniques referencing this article

  • EX-0001.02Bus Traffic ReplayST0004
    addresses
    moderate
    derived

    Limited attack surfaces apply to internal bus interfaces; manufacturers must constrain which transmit nodes can produce traffic for which subscribers.

  • Limited attack surfaces include hardware test/maintenance modes; manufacturers must design products to disable, lock or destroy these surfaces post-deployment.

  • EX-0009.02Operating SystemST0004
    addresses
    moderate
    derived

    Limited attack surfaces obligation requires manufacturers to remove or disable maintenance shells, management consoles and unused kernel primitives in production firmware — exactly the OS-level surface this technique targets.

  • EX-0012.01RegistersST0004
    addresses
    moderate
    derived

    Limited attack surfaces apply to register-level/maintenance interfaces; manufacturers must lock or destroy them post-deployment.

  • EX-0012.02Internal Routing TablesST0004
    addresses
    moderate
    derived

    Limited attack surfaces define which trust domains can publish to which subscribers; manufacturers must enforce these boundaries in routing-table policy.

  • EX-0012.03Memory Write/LoadsST0004
    addresses
    moderate
    derived

    Limited attack surfaces include raw memory-write interfaces; manufacturers must disable or constrain such interfaces post-deployment.

  • EX-0014.02Bus Traffic SpoofingST0004
    addresses
    moderate
    derived

    Limited attack surfaces include bus-segment trust domains; manufacturers must enforce origin restrictions on bus-message production.

  • Secondary purpose-built links (rekeying, emergency commanding, beacons, custodial crosslinks) ARE external interfaces in the (2)(j) sense; the limit-attack-surfaces obligation requires these auxiliary surfaces to be hardened and not available as covert exfiltration paths.

  • EXF-0010Payload Communication ChannelST0008
    addresses
    high
    direct

    Payload comms separate from primary TT&C is exactly the kind of additional external interface (2)(j) requires the product designer to constrain — particularly when bus data can be routed into channels that bypass TT&C monitoring.

  • IA-0003Crosslink via Compromised NeighborST0003
    addresses
    moderate
    derived

    Limited attack surfaces apply to crosslink-facing functions; minimising trust granted to neighboring vehicles bounds the bridgehead-from-neighbor risk.

  • IA-0004Secondary/Backup Communication ChannelST0003
    addresses
    moderate
    derived

    Limited attack surfaces apply to secondary/backup interfaces; manufacturers should design backup channels to be activated only when needed and locked down by default.

  • IA-0004.02ReceiverST0003
    addresses
    moderate
    derived

    Limited attack surfaces apply to backup receivers; cross-strapped or alternate front ends should be locked down except when actively required.

  • IA-0006Compromise Hosted PayloadST0003
    addresses
    high
    derived

    Limited attack surfaces apply to host-bus/payload gateway interfaces; manufacturers must design products to expose minimal trust through these gateways to prevent payload-to-bus pivot.

  • IA-0007Compromise Ground SystemST0003
    addresses
    high
    derived

    Limited attack surfaces apply to ground-system products; manufacturers must minimise external interfaces (admin consoles, debug ports, management APIs) on operator workstations and mission-control servers.

  • IA-0008.02Rogue SpacecraftST0003
    addresses
    moderate
    derived

    Limited attack surfaces on proximity-facing interfaces bound what a rogue-spacecraft peer can interact with even when within RF range.

  • IA-0009.03User SegmentST0003
    addresses
    moderate
    derived

    Limited attack surfaces apply to user-segment-facing interfaces (terminal APIs, customer gateways); products should expose minimal trust through these edges to prevent user-segment compromise propagating into mission systems.

  • IA-0011Auxiliary Device CompromiseST0003
    addresses
    high
    derived

    Limited attack surfaces apply to peripheral and removable-media interfaces; manufacturers must constrain what auxiliary devices can ingest into the product.

  • Limited attack surfaces during AIT-time integration constrain the ingress points adversaries exploit when EGSE, simulators and flatsats touch flight interfaces.

  • IA-0013Compromise Host SpacecraftST0003
    addresses
    high
    derived

    Limited attack surfaces apply to host-bus/payload interfaces from the host-bus side: manufacturer must design the host bus to expose minimal trust to the hosted payload.

  • LM-0001Hosted PayloadST0007
    addresses
    high
    direct

    The host–payload boundary IS an external interface and shared-bus interaction surface; (2)(j)'s limit-attack-surfaces obligation places product-design responsibility on segmenting it.

  • A flat shared bus with minimal partitioning is exactly the unbounded internal attack surface (2)(j)'s limit-attack-surfaces obligation requires the product designer to constrain through segmentation, role enforcement, and gateway controls.

  • LM-0003Constellation Hopping via CrosslinkST0007
    addresses
    moderate
    direct

    Crosslink gateways into command/data paths are an external-interface attack surface; (2)(j)'s limit-attack-surfaces obligation constrains what the gateway accepts from peers.

  • LM-0004Visiting Vehicle Interface(s)ST0007
    addresses
    high
    direct

    Visiting-vehicle interfaces are external interfaces in the most literal (2)(j) sense; the limit-attack-surfaces obligation applies to docking handshakes and umbilical service channels.

  • LM-0005Virtualization EscapeST0007
    addresses
    high
    direct

    Inter-partition communication channels (message ports, shared memory, virtual NICs, hypercalls) ARE the attack surface (2)(j)'s obligation requires the product to limit and harden.

  • LM-0006Launch Vehicle InterfaceST0007
    addresses
    high
    direct

    Umbilicals, separation avionics, and shared EGSE networks are external interfaces (2)(j) requires the product to limit; tight integration timelines are not an exemption from the design obligation.

  • LM-0006.01Rideshare PayloadST0007
    addresses
    high
    direct

    Shared data buses, deployer controllers, and common logging collectors used by rideshare neighbors are the precise multi-tenant attack surface (2)(j)'s limit-attack-surfaces obligation requires payload manufacturers to constrain via isolation.

  • LM-0007Credentialed TraversalST0007
    addresses
    moderate
    inferred

    (2)(j) attack-surface limitation reduces cross-domain gateway count but does not interdict honoring of reused valid credentials; access control and least-privilege scoping (2)(d) interdict the credential-reuse lateral path, so (2)(j) addresses surface exposure.

  • PER-0003Ground System PresenceST0005
    addresses
    high
    derived

    Limited attack surfaces on ground-system products bound the surface where persistent attacker presence can hide; manufacturers must minimise admin consoles, debug ports and management APIs.

  • REC-0003.02Commanding DetailsST0001
    addresses
    moderate
    derived

    Manufacturers must design products to limit attack surfaces, including external interfaces; products that minimise commanding-interface exposure (mode-bound commands, locked-down maintenance dictionaries) reduce the value of commanding-detail reconnaissance.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.