Art. 81(4)
Mapped SPARTA techniques (23)
Techniques referencing this article
Inhibiting ground-system functionality (primary: Art. 81(1) IAM) cascades to (4)'s issuance/management/revocation/audit obligations — credential audit detects compromise of operator workstations.
81(4)'s audit clause on access rights surfaces credentialed-evasion patterns — periodic recertification and behavioral audit limit the value of compromised credentials.
Authentication-process modification (primary: Art. 81(1)) cascades to 81(4) — credential lifecycle audit surfaces anomalous changes to authentication.
Compromised-ground-system exfiltration (primary: Art. 81(1)) cascades to 81(4) — credential audit and revocation discipline limits the scope of compromised credentials harvesting mission data.
Compromised-partner-site exfiltration (primary: Art. 81(1)) cascades to 81(4) — partner-credential lifecycle audit limits cross-organization compromise.
Backup-ground-station compromise (primary: Art. 81(1)) cascades to 81(4) — credential audit on standby-site accounts is part of lifecycle discipline.
Ground-system compromise (primary: Art. 81(1)) cascades to 81(4) — issuance/management/revocation/audit lifecycle discipline limits attacker persistence in the ground segment.
On-orbit-update pipeline compromise (primary: Art. 81(1)) cascades to 81(4) — pipeline-credential audit is part of credential lifecycle.
81(4)'s issuance/management/revocation/audit lifecycle on credentials limits how long compromised operator accounts retain access — the audit clause supports detection of malicious commanding.
Trusted-relationship initial-access (primary: Art. 81(1)) cascades to 81(4) — federated-credential lifecycle audit limits cross-domain reach of inherited trust.
Mission-collaborator compromise (primary: Art. 81(1)) cascades to 81(4) — federated-credential audit on partner accounts is the lifecycle discipline.
81(4)'s issuance/management/revocation/audit lifecycle limits the persistence of vendor credentials beyond engagement scope, reducing the window for vendor-derived compromise.
Theft-impact (primary: Art. 81(1)) is mitigated by 81(4)'s credential audit and revocation lifecycle that limits the population that can access the data stores theft targets.
81(4)'s second subparagraph — the principles of 'need to know' and 'least privilege' — directly limits credential reuse across enclaves.
81(4)'s issuance/management/revocation/audit obligations on credentials directly counter long-lived ground-system residency — periodic recertification limits attacker persistence.
Cryptographic-key replacement (primary: Art. 81(1) IAM on key-loading) cascades to 81(4) — rekey-command audit is part of credential lifecycle discipline applied to key-loading credentials.
81(4)'s issuance/management/revocation/audit lifecycle on credentials limits how long compromised credentials retain access — periodic recertification is the operator-side discipline that defeats long-term credentialed persistence.
Compromise-infrastructure scenarios (primary: Art. 81(1)) cascade to 81(4) — credential lifecycle audit detects unauthorized retention of access on operator infrastructure.
Mission-ground-system compromise (primary: Art. 81(1)) cascades to 81(4) — operator workstation and HSM credential audit is part of the lifecycle discipline.
Third-party-ground-system compromise (primary: Art. 81(1)) cascades to 81(4) — third-party-account credential audit limits attacker dwell time on commercial portals.
Cryptographic-key acquisition by adversaries (primary: Art. 81(1) on key-loading IAM) cascades to 81(4) — credential audit on HSM and key-management identities limits exposure window.
81(4)'s issuance/management/revocation/audit obligations on credentials directly mitigate credential-leakage scenarios — least-privilege limits the population that can hold TT&C keys.
Dev-environment recon (primary: Art. 81(1)) cascades to 81(4) — repository and CI/CD credential audit limits attacker reconnaissance value.