eu-space-act

Art. 84(3)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (24)

Techniques referencing this article

  • DE-0004MasqueradingST0006
    mitigates
    moderate
    direct

    84(3)'s only-authorized-devices rule applies to crosslink and bus participants — preventing masqueraded peer identities from being honored.

  • EX-0001.02Bus Traffic ReplayST0004
    addresses
    moderate
    direct

    84(3)'s only-authorized-devices rule extends to internal bus participants — limiting which on-board nodes can replay or inject historical traffic.

  • 84(3)'s only-authorized-devices rule governs which sources can issue raw hardware commands — preventing maintenance/test interfaces from accepting unsanctioned actor traffic.

  • EX-0012.03Memory Write/LoadsST0004
    addresses
    moderate
    direct

    84(3)'s only-authorized-devices rule governs which sources can issue memory-load commands — preventing unauthorized writes via the command path.

  • EX-0014.02Bus Traffic SpoofingST0004
    addresses
    high
    direct

    84(3)'s only-authorized-devices-communicate rule governs internal-bus participants — preventing forged frames from being honored regardless of identifier validity.

  • EX-0014.03Sensor DataST0004
    addresses
    moderate
    direct

    84(3)'s authorized-devices rule governs sensor gateways — limiting which sensor sources can write into estimation/control pipelines.

  • 84(3)'s only-authorized-devices-communicate rule applies to all command/control surfaces; out-of-band channels need the same authentication discipline as primary TT&C.

  • EXF-0010Payload Communication ChannelST0008
    addresses
    moderate
    direct

    84(3)'s only-authorized-devices rule governs which subsystems can write to payload comms channels — preventing host-bus data from being injected into payload-customer downlinks.

  • Crosslink-borne traffic from a compromised neighbor must be filtered via the only-authorized-devices-communicate-with-control-systems rule under 84(3) — the canonical defense against trusted-neighbor abuse.

  • 84(3)'s only-authorized-devices-communicate rule applies regardless of whether the path is primary or secondary — backup channels need the same authentication discipline.

  • IA-0004.02ReceiverST0003
    addresses
    high
    direct

    Secondary on-board receivers must obey 84(3)'s only-authorized-devices-communicate rule even when activated under safing or maintenance modes.

  • IA-0005.02Docked Vehicle / OSAMST0003
    addresses
    high
    direct

    Docking/OSAM interfaces that push firmware, load tables, or transfer files are controlled-system interfaces under 84(3) — only-authorized-devices governance must apply at the mechanical/electrical bridge.

  • IA-0006Compromise Hosted PayloadST0003
    addresses
    high
    direct

    Hosted-payload command sets that traverse the host bus must obey 84(3)'s only-authorized-devices-communicate rule — payload-host gateway processors are the boundary the obligation applies to.

  • IA-0008Rogue External EntityST0003
    addresses
    high
    direct

    Rogue external entities are the canonical case 84(3)'s only-authorized-devices-communicate-with-control-systems rule defends against — any external transmitter outside the approved set must be filtered.

  • IA-0008.01Rogue Ground StationST0003
    addresses
    high
    direct

    Adversary-fielded ground stations transmitting mission-compatible signals are exactly what 84(3)'s only-authorized-devices rule excludes.

  • IA-0008.02Rogue SpacecraftST0003
    addresses
    high
    direct

    Adversary spacecraft emitting crosslink-compatible signals or relaying user traffic must be filtered by 84(3)'s only-authorized-devices rule on inter-satellite links.

  • IA-0009.03User SegmentST0003
    addresses
    moderate
    direct

    When user-plane messages traverse gateways into control or management planes, 84(3)'s only-authorized-devices rule governs which user terminals can reach control systems.

  • IA-0011Auxiliary Device CompromiseST0003
    addresses
    high
    direct

    Auxiliary devices (USB, removable media, peripherals) that ingest data into mission systems are 'devices' under 84(3)'s only-authorized-devices rule — auto-ingest of tainted media must be governed accordingly.

  • IA-0013Compromise Host SpacecraftST0003
    mitigates
    moderate
    direct

    84(3)'s only-authorized-devices rule applies to host-payload bridges — limiting which host subsystems can issue commands or write to the hosted payload.

  • LM-0001Hosted PayloadST0007
    addresses
    high
    direct

    Hosted payload command sets traversing the host bus must obey 84(3)'s only-authorized-devices-communicate rule at the gateway processor.

  • 84(3)'s only-authorized-devices-communicate rule directly defends against bus participants forging message IDs or impersonating bus controllers.

  • Crosslink hopping between vehicles is precisely the only-authorized-devices scenario 84(3) defends — crafted traffic from a compromised neighbor must be filtered.

  • LM-0004Visiting Vehicle Interface(s)ST0007
    addresses
    high
    direct

    Visiting-vehicle docking interfaces (umbilicals, firmware push channels) must obey 84(3)'s only-authorized-devices-communicate rule.

  • LM-0006Launch Vehicle InterfaceST0007
    addresses
    high
    direct

    Launch-vehicle umbilicals and EGSE networks must obey 84(3)'s only-authorized-devices rule; tight integration timelines are not an exemption.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.