eu-space-act

Art. 81(1)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (23)

Techniques referencing this article

  • Inhibiting ground-system functionality requires access to operator workstations, telemetry processing, or display software — IAM under 81(1) defends these surfaces.

  • DE-0011Credentialed EvasionST0006
    addresses
    high
    direct

    Credentialed evasion is the canonical case 81(1)'s identity-and-access-management protocols defend against — appropriate-control-mechanisms must surface anomalous use of legitimate credentials.

  • EX-0003Modify Authentication ProcessST0004
    addresses
    high
    direct

    Modifying the spacecraft's authentication process — patching command verification routines, hooking handlers, widening anti-replay windows — directly attacks the IAM machinery 81(1) places under operator governance.

  • EXF-0007Compromised Ground SystemST0008
    addresses
    high
    direct

    Compromise of operator workstations, mission control servers, scheduling, and HSMs is the canonical case 81(1)'s identity-and-access-management protocols defend against on the ground segment.

  • EXF-0009Compromised Partner SiteST0008
    addresses
    moderate
    direct

    Cross-organization links (partner-to-MOC) need authenticated boundary controls; 81(1)'s IAM protocols extend to credentials issued for partner integrations.

  • IA-0004.01Ground StationST0003
    addresses
    high
    direct

    Backup ground-station accounts, scheduler/orchestration access, and antenna control are governed by 81(1)'s identity-and-access-management protocols — the same IAM discipline applies to the standby site as to the primary.

  • IA-0007Compromise Ground SystemST0003
    addresses
    high
    direct

    Compromise of operator workstations, mission control servers, scheduling/orchestration, antenna control, and HSMs is the canonical case 81(1)'s identity-and-access-management protocols defend against on the ground segment.

  • IA-0007.01Compromise On-Orbit UpdateST0003
    addresses
    high
    direct

    Update-pipeline manipulation requires access to source repositories, build steps, staging areas, and update metadata — all governed by 81(1)'s IAM protocols.

  • Issuing valid-looking commands from a compromised mission ground system is exactly what 81(1)'s IAM protocols defend — operator credentials and procedures must be restricted to legitimate users.

  • IA-0009Trusted RelationshipST0003
    addresses
    high
    direct

    Federated VPNs, jump hosts, API keys, and identity-provider integrations are governed by 81(1)'s IAM protocols — the discipline that prevents inherited trust from converting into unrestricted access.

  • Federated credentials and delegated authority to collaborators must be governed by 81(1)'s IAM protocols — preventing collaborator-side compromise from cascading into mission enclaves.

  • IA-0009.02VendorST0003
    addresses
    moderate
    direct

    Vendor accounts with elevated, persistent routes into operations are the precise IAM target of 81(1) — least-privilege and lifecycle disciplines limit vendor-derived initial access.

  • IMP-0006TheftST0009
    addresses
    moderate
    direct

    Strict authentication and access-management mechanisms under 81(1) restrict who can access data stores and downlink channels theft would target.

  • LM-0007Credentialed TraversalST0007
    addresses
    high
    direct

    Credentialed traversal across enclaves is the canonical IAM-failure case 81(1) defends — appropriate-control-mechanisms must scope credentials to limit cross-domain reach.

  • PER-0003Ground System PresenceST0005
    addresses
    high
    direct

    Persistent ground-system access is the canonical case 81(1)'s identity-and-access-management protocols defend against — credential lifecycle and audit are the discipline that detects and revokes residency.

  • PER-0004Replace Cryptographic KeysST0005
    addresses
    high
    direct

    Key-loading procedures are critical-function actions governed by 81(1)'s IAM protocols — only the highest-privilege identities should authorize rekey events.

  • PER-0005Credentialed PersistenceST0005
    addresses
    high
    direct

    Credentialed persistence — leveraging valid credentials to maintain access — is the canonical case 81(1)'s identity-and-access-management protocols defend against on the spacecraft and ground systems.

  • RD-0002Compromise InfrastructureST0002
    addresses
    high
    direct

    Compromise of mission-owned infrastructure (mission control, automation, identity providers) is the canonical case 81(1)'s identity-and-access-management protocols defend against.

  • Compromise of the mission's own ground system (operator workstations, mission control servers, key-loading tools, antenna control) is exactly what 81(1)'s identity-and-access-management protocols defend.

  • RD-0002.023rd Party Ground SystemST0002
    addresses
    moderate
    direct

    Operator-side IAM under 81(1) extends to credentials issued to third-party-station accounts and APIs — preventing customer-credential abuse on the operator's behalf.

  • RD-0003.02Cryptographic KeysST0002
    addresses
    moderate
    direct

    Operator IAM protocols under 81(1) restrict access to HSMs, key-loading tools, and key-recovery procedures — limiting the population that can abscond with cryptographic material.

  • REC-0003.04Valid CredentialsST0001
    addresses
    high
    direct

    TT&C authentication keys, link-encryption keys, and operator credentials are exactly the access-rights material 81(1)'s identity-and-access-management protocols govern.

  • REC-0006.01Development EnvironmentST0001
    addresses
    moderate
    direct

    Identity-and-access-management protocols under 81(1) govern the dev-environment credentials, repository access, and CI/CD orchestrator permissions.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.