eu-space-act

Art. 84(2)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (57)

Techniques referencing this article

  • DE-0001Disable Fault ManagementST0006
    addresses
    high
    direct

    Disabling FDIR rewrites parameter/limit tables, voting logic, and event routing — network-and-information-system integrity covered by 84(2)'s Annex VII point 5.1 compliance.

  • DE-0002Disrupt or Deceive DownlinkST0006
    addresses
    high
    direct

    Downlink disruption/deception attacks the integrity and availability of the network-and-information-system telemetry channel — within 84(2)'s Annex VII point 5.1 scope.

  • Falsifying telemetry within ground processing pipelines attacks integrity of network-and-information-system data — 84(2)'s Annex VII point 5.1 compliance covers ground-side processing integrity.

  • On-board telemetry-publisher manipulation alters network-and-information-system integrity — 84(2)'s Annex VII point 5.1 covers the configuration of these publishers.

  • DE-0003On-Board Values ObfuscationST0006
    addresses
    high
    direct

    On-board values obfuscation rewrites housekeeping, counters, and mode indicators — network-and-information-system data whose integrity 84(2)'s Annex VII point 5.1 must protect.

  • Vehicle Command Counter is core network-and-information-system state under 84(2)'s Annex VII point 5.1 — manipulation of the counter or the field that reports it is integrity tampering.

  • DE-0003.02Rejected Command CounterST0006
    addresses
    high
    direct

    Rejected Command Counter manipulation tampers with stored network-and-information-system state under 84(2)'s integrity scope.

  • Toggling receiver enable states alters network-and-information-system configuration under 84(2)'s Annex VII point 5.1 scope.

  • AGC and signal-strength parameter manipulation alters receiver configuration covered by 84(2)'s Annex VII point 5.1.

  • DE-0003.05Command Receiver Lock ModesST0006
    addresses
    high
    direct

    Command-lock indicator tampering rewrites stored network-and-information-system status — 84(2)'s Annex VII point 5.1 integrity scope.

  • DE-0003.06Telemetry Downlink ModesST0006
    addresses
    high
    direct

    Telemetry mode/rate/filter configuration is network-and-information-system state under 84(2) — Annex VII point 5.1 includes integrity protection for monitoring-channel configuration.

  • DE-0003.08Received CommandsST0006
    addresses
    high
    direct

    Editing or pruning command-history buffers tampers with stored network-and-information-system records — within 84(2)'s integrity scope per Annex VII point 5.1.

  • DE-0003.09System Clock for EvasionST0006
    addresses
    moderate
    direct

    System-clock biasing attacks the network-and-information-system time integrity per 84(2)'s Annex VII point 5.1 requirements.

  • DE-0003.10GPS EphemerisST0006
    addresses
    moderate
    direct

    Spoofed GPS ephemeris feeding into telemetered position estimates corrupts network-and-information-system data — within 84(2)'s integrity scope.

  • DE-0003.11Watchdog Timer (WDT) for EvasionST0006
    addresses
    moderate
    direct

    Watchdog parameter manipulation rewrites network-and-information-system supervision configuration — 84(2)'s Annex VII point 5.1 integrity scope.

  • DE-0003.12Poison AI/ML Training for EvasionST0006
    addresses
    moderate
    direct

    Poisoned training data corrupts the model the network-and-information-system relies on for monitoring — 84(2)'s integrity scope under Annex VII point 5.1.

  • DE-0006Modify WhitelistST0006
    addresses
    high
    direct

    Whitelist modification rewrites a security-critical configuration table — within 84(2)'s integrity scope per Annex VII point 5.1.

  • DE-0007Evasion via RootkitST0006
    addresses
    high
    direct

    Rootkits patch FSW APIs, kernel syscalls, and message queues — directly attacking the integrity properties of the network-and-information-system per 84(2)'s Annex VII point 5.1.

  • DE-0008Evasion via BootkitST0006
    addresses
    high
    direct

    Bootkit attacks the boot-chain integrity covered by 84(2)'s Annex VII point 5.1 — secure-boot, root-of-trust, and verified-boot are the foundational integrity protections.

  • Art. 84(2)'s comply-with-Annex-VII-5.1 reference is domain-relevant to sensor deception but names no specific interdicting mechanism; sensor-fusion validation would be the interdiction.

  • Compromise/spoofing of ground-SDA observational feeds and falsified-track injection corrupts network-and-information-system data — 84(2)'s Annex VII point 5.1 integrity scope applies to ground SDA pipelines.

  • DE-0010Overflow Audit LogST0006
    addresses
    moderate
    inferred

    Art. 84(2)'s comply-with-Annex-VII-5.1 reference is domain-relevant to log-overflow, but names no specific interdicting mechanism in the cited text.

  • EX-0001.02Bus Traffic ReplayST0004
    addresses
    high
    direct

    Internal-bus replay attacks the network-and-information-system properties under 84(2) — Annex VII point 5.1 requirements include integrity and authentication on internal buses.

  • EX-0003Modify Authentication ProcessST0004
    addresses
    moderate
    inferred

    Art. 84(2)'s comply-with-Annex-VII-5.1 reference is domain-relevant to authentication-process modification but names no specific interdicting mechanism in the cited text.

  • EX-0004Compromise Boot MemoryST0004
    addresses
    moderate
    inferred

    Art. 84(2)'s comply-with-Annex-VII-5.1 reference is domain-relevant to boot-chain compromise, but names no specific interdicting mechanism in the cited text; secure-boot signature verification would be the interdiction.

  • EX-0005Exploit Hardware/Firmware CorruptionST0004
    addresses
    moderate
    inferred

    Art. 84(2)'s comply-with-Annex-VII-5.1 reference is domain-relevant to below-OS exploitation but names no specific interdicting mechanism in the cited text.

  • EX-0010.04BootkitST0004
    addresses
    high
    direct

    Bootkit attacks the integrity of the boot chain; 84(2)'s requirement that network and information systems comply with Annex VII point 5.1 includes secure-boot and root-of-trust as foundational protections.

  • EX-0012Modify On-Board ValuesST0004
    addresses
    high
    direct

    Modifying live or persistent on-board values attacks the integrity of network and information systems; 84(2)'s Annex VII point 5.1 compliance includes integrity protection on the data structures EX-0012 targets.

  • EX-0012.02Internal Routing TablesST0004
    addresses
    high
    direct

    Internal routing tables (1553 RT/SA, SpaceWire node/port, CAN ID maps) are network-and-information-system configuration covered by 84(2)'s Annex VII point 5.1 integrity requirements.

  • EX-0012.04App/Subscriber TablesST0004
    addresses
    moderate
    direct

    App/subscriber tables in pub/sub flight frameworks are network-and-information-system state under 84(2) — Annex VII point 5.1 includes integrity protection on subscription bindings.

  • EX-0012.06Science/Payload DataST0004
    addresses
    moderate
    inferred

    Art. 84(2)'s comply-with-Annex-VII-5.1 reference is domain-relevant to payload-data modification, but the cited text names no specific interdicting mechanism; integrity protection (signing) of the data would be the interdiction.

  • ADCS configuration tables held in network and information systems require 84(2)'s integrity protections per Annex VII point 5.1.

  • EX-0012.09Electrical Power SubsystemST0004
    addresses
    moderate
    inferred

    Art. 84(2)'s comply-with-Annex-VII-5.1 reference is domain-relevant to EPS-config modification but names no specific interdicting mechanism in the cited text.

  • C&DH is the canonical mission network-and-information-system; 84(2)'s Annex VII point 5.1 compliance includes integrity on dispatch/route configuration.

  • EX-0012.11Watchdog Timer (WDT)ST0004
    addresses
    high
    direct

    Watchdog Timer configuration (timeout durations, reset actions, enable bits) is mission-system integrity covered by 84(2)'s Annex VII point 5.1 requirements.

  • EX-0012.12System ClockST0004
    addresses
    high
    direct

    System clock state is foundational to integrity of network-and-information-system data; 84(2)'s Annex VII point 5.1 covers time-distribution integrity.

  • EX-0013FloodingST0004
    addresses
    moderate
    direct

    Flooding attacks the availability properties of network-and-information-system; 84(2)'s Annex VII point 5.1 compliance includes rate limiting and queue-management against saturation.

  • EX-0013.01Valid CommandsST0004
    addresses
    moderate
    direct

    Rate/size limits on the command path are network-and-information-system properties under 84(2)'s Annex VII point 5.1 scope.

  • EX-0013.02Erroneous InputST0004
    addresses
    moderate
    direct

    Erroneous-input flooding attacks the parser/decoder layers — 84(2)'s Annex VII point 5.1 compliance includes resilience to malformed-input handling.

  • EX-0014.01Time SpoofST0004
    addresses
    moderate
    direct

    Time integrity is foundational to network-and-information-system; 84(2)'s Annex VII point 5.1 covers protection of distributed-time service.

  • EX-0014.02Bus Traffic SpoofingST0004
    addresses
    high
    direct

    Internal-bus message authentication is part of 84(2)'s Annex VII point 5.1 compliance — bus traffic with valid identifiers from unauthorized sources must be filtered.

  • EX-0014.03Sensor DataST0004
    addresses
    high
    direct

    Sensor-data integrity is part of network-and-information-system properties under 84(2)'s Annex VII point 5.1; spoofed sensor frames at gateways must be filtered.

  • Art. 84(2)'s comply-with-Annex-VII-5.1 reference is domain-relevant to PNT spoofing, but names no specific interdicting mechanism; authenticated time and ephemeris validation would interdict.

  • Secondary purpose-built links (rekeying, emergency commanding, beacons, custodial crosslinks) are network-and-information-system surfaces under 84(2)'s Annex VII point 5.1 scope — security obligations apply to auxiliary paths, not just primary TT&C.

  • Retuning carriers, editing modulation/coding profiles, and remapping virtual channels are unauthorized modifications of network-and-information-system communications configuration — within 84(2)'s Annex VII point 5.1 integrity scope.

  • EXF-0006.01Software Defined RadioST0008
    addresses
    moderate
    direct

    SDR DSP chain modifications (filters, mixers, FEC, framing) attack network-and-information-system program/config integrity — 84(2)'s Annex VII point 5.1 scope.

  • EXF-0006.02TransponderST0008
    addresses
    high
    direct

    Transponder I/O remapping and routing-table edits are unauthorized modifications of network-and-information-system configuration — 84(2)'s Annex VII point 5.1 integrity scope.

  • EXF-0010Payload Communication ChannelST0008
    addresses
    moderate
    direct

    Routing host-bus data into payload comms channels manipulates network-and-information-system data flow — 84(2)'s Annex VII point 5.1 integrity scope covers payload-bus segregation.

  • IA-0002Compromise Software Defined RadioST0003
    addresses
    moderate
    inferred

    Art. 84(2)'s comply-with-Annex-VII-5.1 reference is domain-relevant to SDR-plane compromise, but names no specific interdicting mechanism in the cited text.

  • Backup/contingency channels are network and information systems within 84(2)'s scope — the requirement that they comply with Annex VII point 5.1 covers their security posture, not just the primary TT&C.

  • IMP-0001Deception (or Misdirection)ST0009
    addresses
    high
    direct

    Modifying telemetry values to mislead mission stakeholders is the canonical case 84(2)'s integrity property addresses — Annex VII point 5.1 includes integrity protection on transmitted data.

  • LM-0002Exploit Lack of Bus SegregationST0007
    addresses
    moderate
    direct

    Flat shared-bus architecture is a network-and-information-system property under 84(2) — Annex VII point 5.1 requires segmentation, role enforcement, and integrity protection to limit the attack surface.

  • LM-0005Virtualization EscapeST0007
    addresses
    moderate
    direct

    Hypervisor escape attacks the integrity boundary 84(2)'s Annex VII point 5.1 requires for separation kernels and partitioned environments.

  • PER-0001Memory CompromiseST0005
    addresses
    moderate
    direct

    Memory-compromise persistence rides non-volatile images, configuration words, and auto-run hooks — 84(2)'s Annex VII point 5.1 compliance includes integrity protection on these foundational storage areas.

  • RD-0002Compromise InfrastructureST0002
    addresses
    moderate
    inferred

    Art. 84(2)'s comply-with-Annex-VII-5.1 reference is domain-relevant to infrastructure compromise but names no specific interdicting mechanism in the cited text.

  • REC-0001.04Data BusST0001
    addresses
    moderate
    inferred

    Art. 84(2)'s comply-with-Annex-VII-5.1 reference is domain-relevant to bus-design exposure, but names no mechanism interdicting the reconnaissance; it is design-discipline governance, not vector interdiction.

  • Art. 84(2)'s requirement to comply with Annex VII point 5.1 governs network-and-information-system protection in this technique's domain, but the cited text names no mechanism interdicting passive link interception; it establishes domain relevance, not vector interdiction. Link encryption or emission control would be the interdicting mitigation.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.