Art. 78(1)
Mapped SPARTA techniques (9)
Techniques referencing this article
PNT-geofenced payloads embed conditional triggers in flight code — 78(1)(c)'s identify-cybersecurity-vulnerabilities obligation covers detection of conditional malicious behavior during code review and runtime analysis.
Hardware design-flaw exploitation depends on errata and undocumented behaviors that 78(1)(c) requires the operator to identify as cybersecurity vulnerabilities — the precise discipline that surfaces these flaws.
Code-flaw exploitation is the canonical case 78(1)(c)'s identify-cybersecurity-vulnerabilities obligation addresses; (d) requires risk-treatment plans for vulnerabilities above acceptable risk.
Flight-software defects (unchecked lengths, arithmetic overflows, table-content validation) are the cybersecurity vulnerabilities 78(1)(c) requires the operator to identify continuously; (d) requires risk-treatment plans for FSW vulnerabilities above acceptable risk.
OS-layer exploitation depends on kernel/driver vulnerabilities — 78(1)(c)'s identify-cybersecurity-vulnerabilities obligation extends to the operating-system stack of mission systems.
78(1)(c)'s identify-vulnerabilities obligation explicitly covers components and versions whose CPE/CVE mappings expose the spacecraft — the canonical use case for 78(1)(d) risk-treatment plans.
Malicious-code execution requires vulnerable code paths or weak input validation — 78(1)(c)'s identify-vulnerabilities obligation extends to the application logic and interpreter pathways malicious code rides.
78(1)(c)'s identify-cybersecurity-vulnerabilities obligation extends to backdoors discovered through code/hardware audit — risk-treatment plans under (d) follow.
78(1)(c) requires operators to identify cybersecurity vulnerabilities and analyse them when they cannot be fixed immediately; (d) requires risk treatment plans for vulnerabilities above acceptable risk — directly addressing known-vulnerability exposure.