Art. 81(1)
Mapped SPARTA techniques (23)
Techniques referencing this article
Inhibiting ground-system functionality requires access to operator workstations, telemetry processing, or display software — IAM under 81(1) defends these surfaces.
Credentialed evasion is the canonical case 81(1)'s identity-and-access-management protocols defend against — appropriate-control-mechanisms must surface anomalous use of legitimate credentials.
Modifying the spacecraft's authentication process — patching command verification routines, hooking handlers, widening anti-replay windows — directly attacks the IAM machinery 81(1) places under operator governance.
Compromise of operator workstations, mission control servers, scheduling, and HSMs is the canonical case 81(1)'s identity-and-access-management protocols defend against on the ground segment.
Cross-organization links (partner-to-MOC) need authenticated boundary controls; 81(1)'s IAM protocols extend to credentials issued for partner integrations.
Backup ground-station accounts, scheduler/orchestration access, and antenna control are governed by 81(1)'s identity-and-access-management protocols — the same IAM discipline applies to the standby site as to the primary.
Compromise of operator workstations, mission control servers, scheduling/orchestration, antenna control, and HSMs is the canonical case 81(1)'s identity-and-access-management protocols defend against on the ground segment.
Update-pipeline manipulation requires access to source repositories, build steps, staging areas, and update metadata — all governed by 81(1)'s IAM protocols.
Issuing valid-looking commands from a compromised mission ground system is exactly what 81(1)'s IAM protocols defend — operator credentials and procedures must be restricted to legitimate users.
Federated VPNs, jump hosts, API keys, and identity-provider integrations are governed by 81(1)'s IAM protocols — the discipline that prevents inherited trust from converting into unrestricted access.
Federated credentials and delegated authority to collaborators must be governed by 81(1)'s IAM protocols — preventing collaborator-side compromise from cascading into mission enclaves.
Vendor accounts with elevated, persistent routes into operations are the precise IAM target of 81(1) — least-privilege and lifecycle disciplines limit vendor-derived initial access.
Strict authentication and access-management mechanisms under 81(1) restrict who can access data stores and downlink channels theft would target.
Credentialed traversal across enclaves is the canonical IAM-failure case 81(1) defends — appropriate-control-mechanisms must scope credentials to limit cross-domain reach.
Persistent ground-system access is the canonical case 81(1)'s identity-and-access-management protocols defend against — credential lifecycle and audit are the discipline that detects and revokes residency.
Key-loading procedures are critical-function actions governed by 81(1)'s IAM protocols — only the highest-privilege identities should authorize rekey events.
Credentialed persistence — leveraging valid credentials to maintain access — is the canonical case 81(1)'s identity-and-access-management protocols defend against on the spacecraft and ground systems.
Compromise of mission-owned infrastructure (mission control, automation, identity providers) is the canonical case 81(1)'s identity-and-access-management protocols defend against.
Compromise of the mission's own ground system (operator workstations, mission control servers, key-loading tools, antenna control) is exactly what 81(1)'s identity-and-access-management protocols defend.
Operator-side IAM under 81(1) extends to credentials issued to third-party-station accounts and APIs — preventing customer-credential abuse on the operator's behalf.
Operator IAM protocols under 81(1) restrict access to HSMs, key-loading tools, and key-recovery procedures — limiting the population that can abscond with cryptographic material.
TT&C authentication keys, link-encryption keys, and operator credentials are exactly the access-rights material 81(1)'s identity-and-access-management protocols govern.
Identity-and-access-management protocols under 81(1) govern the dev-environment credentials, repository access, and CI/CD orchestrator permissions.