eu-space-act

Art. 80(3)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (26)

Techniques referencing this article

  • EX-0012.06Science/Payload DataST0004
    addresses
    moderate
    direct

    Payload data and metadata (timestamps, calibration coefficients, quality flags) require 80(3)'s integrity categorization — the rationale clause 'the need to ensure the confidentiality, integrity, authenticity and availability of information' explicitly extends to data products.

  • EXF-0003Signal InterceptionST0008
    addresses
    moderate
    inferred

    Art. 80(3)'s information categorization is domain-relevant to interception (it drives crypto policy), but categorization itself does not interdict the interception.

  • EXF-0003.02Downlink ExfiltrationST0008
    addresses
    moderate
    inferred

    Art. 80(3)'s information categorization is domain-relevant to downlink exfiltration (it drives crypto policy), but categorization itself does not interdict the exfiltration.

  • IMP-0006TheftST0009
    addresses
    moderate
    inferred

    Art. 80(3)'s information categorization is domain-relevant to theft (it drives encryption policy), but categorization itself does not interdict the exfiltration.

  • Spacecraft design information (avionics architecture, ICDs, SBOMs, AIT travelers) is exactly what 80(3) requires the operator to categorize by confidentiality, integrity, authenticity, and availability needs.

  • REC-0001.01Software DesignST0001
    addresses
    high
    direct

    Flight/ground software details (RTOS versions, command handlers, crypto libraries, patch mechanisms) require the confidentiality categorization 80(3) places on operator information assets.

  • REC-0001.02FirmwareST0001
    addresses
    high
    direct

    Firmware images, bitstreams, and secure-boot settings are sensitive operator-held artifacts that 80(3)'s information-security categorization must cover.

  • REC-0001.03Cryptographic AlgorithmsST0001
    addresses
    high
    direct

    Crypto algorithm/key documentation is high-confidentiality operator information that 80(3) requires to be categorized accordingly.

  • REC-0001.04Data BusST0001
    addresses
    high
    direct

    Bus topology, message IDs, schedule tables, and harness pinouts are high-confidentiality design artifacts requiring 80(3)'s information-security categorization.

  • REC-0001.05Thermal Control SystemST0001
    addresses
    moderate
    direct

    Thermal control system internals (TMM models, heater maps, autonomy rules) are operator-held artifacts whose disclosure reveals stress points; 80(3) places confidentiality categorization on this information.

  • REC-0001.06Maneuver & ControlST0001
    addresses
    high
    direct

    GNC stack details (control laws, estimator design, propulsion plume keep-out zones) are sensitive design artifacts that 80(3)'s confidentiality categorization must cover; loss of effective technical control of the space mission turns on protecting this data.

  • REC-0001.07PayloadST0001
    addresses
    high
    direct

    Payload ICDs reveal addresses, message IDs, gateway locations, and crypto-posture differences with the bus — high-confidentiality operator artifacts within 80(3)'s categorization scope.

  • REC-0001.08PowerST0001
    addresses
    moderate
    direct

    EPS topology, MPPT algorithms, BMS limits, and load-shed priorities are sensitive design artifacts that 80(3)'s confidentiality categorization must cover.

  • REC-0001.09Fault ManagementST0001
    addresses
    high
    direct

    FDIR/autonomy/safing materials (fault trees, FMEAs, autonomy rule tables, safe-mode entry/exit criteria) are high-confidentiality artifacts essential to mission resilience — within 80(3)'s information-security categorization scope.

  • REC-0002Gather Spacecraft DescriptorsST0001
    addresses
    moderate
    direct

    Even though some descriptors (NORAD/COSPAR) are public, operational descriptors (pass windows, staffing patterns, ground-network affiliations) are operator-controlled information that 80(3) requires to be categorized for confidentiality.

  • REC-0002.03OperationsST0001
    addresses
    high
    direct

    CONOPS overviews, daily/weekly activity rhythms, ground pass schedules, and contingency playbooks are operator-controlled operational descriptors whose disclosure cascades into timing-attack capability — within 80(3)'s information categorization scope.

  • Comm posture details (frequency allocations, link budgets, antenna characteristics, station geometries) are operator-controlled artifacts that 80(3) categorizes for confidentiality.

  • REC-0003.01Communications EquipmentST0001
    addresses
    moderate
    direct

    RF-equipment specifics (antenna types, transponder behavior, modem settings) are sensitive operator-held artifacts requiring 80(3)'s confidentiality categorization.

  • REC-0003.02Commanding DetailsST0001
    addresses
    moderate
    direct

    Telecommand framing, authentication scheme details, command-dictionary formats, and timetag rules are highly sensitive operator artifacts within 80(3)'s confidentiality categorization scope.

  • Mission-specific channel configurations (carrier plans, burst structures, gateway locations) are operator-controlled artifacts within 80(3)'s scope.

  • REC-0004Gather Launch InformationST0001
    addresses
    moderate
    direct

    Operator-controlled launch artifacts (range telemetry configurations, integrator touchpoints, internal launch schedules beyond public manifest) are within 80(3)'s categorization scope.

  • REC-0004.01Flight TerminationST0001
    addresses
    high
    direct

    Flight Termination System architecture (authority chains, cryptographic protections, arming interlocks) is high-confidentiality operator/range information within 80(3)'s scope.

  • REC-0005.02Downlink InterceptST0001
    addresses
    moderate
    inferred

    Art. 80(3)'s information categorization is domain-relevant to downlink eavesdropping (it drives crypto policy), but categorization itself does not interdict the reconnaissance.

  • REC-0006Gather FSW Development InformationST0001
    addresses
    moderate
    direct

    Source trees, SBOMs, CI/CD configs, and code-signing workflows are operator-held information artifacts within 80(3)'s confidentiality categorization scope.

  • REC-0006.02Security Testing ToolsST0001
    addresses
    moderate
    direct

    Test-tool inventories, fuzzer corpora, and coverage thresholds are operator-held artifacts whose disclosure reveals untested attack surfaces — 80(3)'s categorization applies.

  • REC-0009Gather Mission InformationST0001
    addresses
    moderate
    direct

    Mission CONOPS, mode logic, and operational constraints are operator-controlled artifacts; while some elements are public, internal documents (algorithms, calibration methods, contingency CONOPS) are within 80(3)'s confidentiality categorization scope.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.