eu-space-act

Art. 81(4)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (23)

Techniques referencing this article

  • Inhibiting ground-system functionality (primary: Art. 81(1) IAM) cascades to (4)'s issuance/management/revocation/audit obligations — credential audit detects compromise of operator workstations.

  • DE-0011Credentialed EvasionST0006
    addresses
    high
    direct

    81(4)'s audit clause on access rights surfaces credentialed-evasion patterns — periodic recertification and behavioral audit limit the value of compromised credentials.

  • EX-0003Modify Authentication ProcessST0004
    addresses
    moderate
    direct

    Authentication-process modification (primary: Art. 81(1)) cascades to 81(4) — credential lifecycle audit surfaces anomalous changes to authentication.

  • EXF-0007Compromised Ground SystemST0008
    addresses
    high
    direct

    Compromised-ground-system exfiltration (primary: Art. 81(1)) cascades to 81(4) — credential audit and revocation discipline limits the scope of compromised credentials harvesting mission data.

  • EXF-0009Compromised Partner SiteST0008
    addresses
    moderate
    direct

    Compromised-partner-site exfiltration (primary: Art. 81(1)) cascades to 81(4) — partner-credential lifecycle audit limits cross-organization compromise.

  • IA-0004.01Ground StationST0003
    addresses
    moderate
    direct

    Backup-ground-station compromise (primary: Art. 81(1)) cascades to 81(4) — credential audit on standby-site accounts is part of lifecycle discipline.

  • IA-0007Compromise Ground SystemST0003
    addresses
    high
    direct

    Ground-system compromise (primary: Art. 81(1)) cascades to 81(4) — issuance/management/revocation/audit lifecycle discipline limits attacker persistence in the ground segment.

  • IA-0007.01Compromise On-Orbit UpdateST0003
    addresses
    moderate
    direct

    On-orbit-update pipeline compromise (primary: Art. 81(1)) cascades to 81(4) — pipeline-credential audit is part of credential lifecycle.

  • IA-0007.02Malicious Commanding via Valid GSST0003
    addresses
    moderate
    direct

    81(4)'s issuance/management/revocation/audit lifecycle on credentials limits how long compromised operator accounts retain access — the audit clause supports detection of malicious commanding.

  • IA-0009Trusted RelationshipST0003
    addresses
    high
    direct

    Trusted-relationship initial-access (primary: Art. 81(1)) cascades to 81(4) — federated-credential lifecycle audit limits cross-domain reach of inherited trust.

  • Mission-collaborator compromise (primary: Art. 81(1)) cascades to 81(4) — federated-credential audit on partner accounts is the lifecycle discipline.

  • IA-0009.02VendorST0003
    addresses
    moderate
    direct

    81(4)'s issuance/management/revocation/audit lifecycle limits the persistence of vendor credentials beyond engagement scope, reducing the window for vendor-derived compromise.

  • IMP-0006TheftST0009
    addresses
    moderate
    direct

    Theft-impact (primary: Art. 81(1)) is mitigated by 81(4)'s credential audit and revocation lifecycle that limits the population that can access the data stores theft targets.

  • LM-0007Credentialed TraversalST0007
    mitigates
    moderate
    direct

    81(4)'s second subparagraph — the principles of 'need to know' and 'least privilege' — directly limits credential reuse across enclaves.

  • PER-0003Ground System PresenceST0005
    addresses
    high
    direct

    81(4)'s issuance/management/revocation/audit obligations on credentials directly counter long-lived ground-system residency — periodic recertification limits attacker persistence.

  • PER-0004Replace Cryptographic KeysST0005
    addresses
    moderate
    direct

    Cryptographic-key replacement (primary: Art. 81(1) IAM on key-loading) cascades to 81(4) — rekey-command audit is part of credential lifecycle discipline applied to key-loading credentials.

  • PER-0005Credentialed PersistenceST0005
    mitigates
    moderate
    direct

    81(4)'s issuance/management/revocation/audit lifecycle on credentials limits how long compromised credentials retain access — periodic recertification is the operator-side discipline that defeats long-term credentialed persistence.

  • RD-0002Compromise InfrastructureST0002
    addresses
    moderate
    direct

    Compromise-infrastructure scenarios (primary: Art. 81(1)) cascade to 81(4) — credential lifecycle audit detects unauthorized retention of access on operator infrastructure.

  • RD-0002.01Mission-Operated Ground SystemST0002
    addresses
    moderate
    direct

    Mission-ground-system compromise (primary: Art. 81(1)) cascades to 81(4) — operator workstation and HSM credential audit is part of the lifecycle discipline.

  • RD-0002.023rd Party Ground SystemST0002
    addresses
    moderate
    direct

    Third-party-ground-system compromise (primary: Art. 81(1)) cascades to 81(4) — third-party-account credential audit limits attacker dwell time on commercial portals.

  • RD-0003.02Cryptographic KeysST0002
    addresses
    moderate
    direct

    Cryptographic-key acquisition by adversaries (primary: Art. 81(1) on key-loading IAM) cascades to 81(4) — credential audit on HSM and key-management identities limits exposure window.

  • REC-0003.04Valid CredentialsST0001
    addresses
    moderate
    direct

    81(4)'s issuance/management/revocation/audit obligations on credentials directly mitigate credential-leakage scenarios — least-privilege limits the population that can hold TT&C keys.

  • REC-0006.01Development EnvironmentST0001
    addresses
    moderate
    direct

    Dev-environment recon (primary: Art. 81(1)) cascades to 81(4) — repository and CI/CD credential audit limits attacker reconnaissance value.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.