eu-space-act

Art. 78(1)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (9)

Techniques referencing this article

  • PNT-geofenced payloads embed conditional triggers in flight code — 78(1)(c)'s identify-cybersecurity-vulnerabilities obligation covers detection of conditional malicious behavior during code review and runtime analysis.

  • EX-0005.01Design FlawsST0004
    addresses
    high
    direct

    Hardware design-flaw exploitation depends on errata and undocumented behaviors that 78(1)(c) requires the operator to identify as cybersecurity vulnerabilities — the precise discipline that surfaces these flaws.

  • EX-0009Exploit Code FlawsST0004
    addresses
    high
    direct

    Code-flaw exploitation is the canonical case 78(1)(c)'s identify-cybersecurity-vulnerabilities obligation addresses; (d) requires risk-treatment plans for vulnerabilities above acceptable risk.

  • EX-0009.01Flight SoftwareST0004
    addresses
    high
    direct

    Flight-software defects (unchecked lengths, arithmetic overflows, table-content validation) are the cybersecurity vulnerabilities 78(1)(c) requires the operator to identify continuously; (d) requires risk-treatment plans for FSW vulnerabilities above acceptable risk.

  • EX-0009.02Operating SystemST0004
    addresses
    high
    direct

    OS-layer exploitation depends on kernel/driver vulnerabilities — 78(1)(c)'s identify-cybersecurity-vulnerabilities obligation extends to the operating-system stack of mission systems.

  • 78(1)(c)'s identify-vulnerabilities obligation explicitly covers components and versions whose CPE/CVE mappings expose the spacecraft — the canonical use case for 78(1)(d) risk-treatment plans.

  • EX-0010Malicious CodeST0004
    addresses
    moderate
    direct

    Malicious-code execution requires vulnerable code paths or weak input validation — 78(1)(c)'s identify-vulnerabilities obligation extends to the application logic and interpreter pathways malicious code rides.

  • PER-0002BackdoorST0005
    addresses
    moderate
    direct

    78(1)(c)'s identify-cybersecurity-vulnerabilities obligation extends to backdoors discovered through code/hardware audit — risk-treatment plans under (d) follow.

  • REC-0008.03Known VulnerabilitiesST0001
    addresses
    high
    direct

    78(1)(c) requires operators to identify cybersecurity vulnerabilities and analyse them when they cannot be fixed immediately; (d) requires risk treatment plans for vulnerabilities above acceptable risk — directly addressing known-vulnerability exposure.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.