eu-space-act

Art. 85(2)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (32)

Techniques referencing this article

  • DE-0003.07Cryptographic ModesST0006
    addresses
    moderate
    direct

    Cryptographic-mode manipulation (primary: Art. 85(1)/(3)) cascades to 85(2)'s key lifecycle — generation, use, and rotation discipline limits adversary ability to flip to attacker-favored profiles.

  • DE-0003.09System Clock for EvasionST0006
    addresses
    moderate
    inferred

    Art. 85(2)'s key-lifecycle policy is crypto-domain-relevant to DE-0003.09, but key lifecycle does not interdict clock-source biasing; authenticated time distribution would be the interdicting mechanism.

  • DE-0004MasqueradingST0006
    addresses
    moderate
    direct

    Masquerading (primary: Art. 85(1)/(3)) cascades to 85(2) — key lifecycle policy ensures masquerading-relevant keys (signing/MAC) follow secure generation/storage/rotation.

  • EX-0001ReplayST0004
    addresses
    high
    direct

    Replay (primary: Art. 85(1)/(3)) cascades to 85(2) — anti-replay counters and key rotation are part of the key lifecycle policy.

  • EX-0001.01Command PacketsST0004
    addresses
    moderate
    direct

    85(2)'s key lifecycle policy includes counter management and key rotation — limiting the operational window in which captured commands can be replayed against extant keys.

  • EX-0006Disable/Bypass EncryptionST0004
    addresses
    moderate
    direct

    85(2)'s key lifecycle policy can prevent downgrade-via-key-substitution by enforcing per-mission key versioning and counter discipline.

  • EX-0012.12System ClockST0004
    addresses
    moderate
    inferred

    Art. 85(2)'s key-lifecycle policy is crypto-domain-relevant to clock manipulation, but does not interdict time-source manipulation; authenticated time distribution would interdict.

  • EX-0014SpoofingST0004
    addresses
    moderate
    direct

    Spoofing parent (primary: Art. 85(1)/(3)) cascades to 85(2) — key lifecycle includes counter discipline against spoofed-input acceptance.

  • EX-0014.01Time SpoofST0004
    addresses
    moderate
    inferred

    Art. 85(2)'s key-lifecycle policy is crypto-domain-relevant to EX-0014.01, but key lifecycle does not interdict time-source spoofing; authenticated time distribution would be the interdicting mechanism.

  • EX-0015Side-Channel AttackST0004
    addresses
    moderate
    direct

    Side-channel attack (primary: Art. 85(1)) cascades to 85(2) — key rotation limits the value of keys recovered through side channels.

  • EXF-0001ReplayST0008
    addresses
    moderate
    direct

    Replay exfiltration (primary: Art. 85(1)/(3)) cascades to 85(2) — counter discipline within key lifecycle limits the operational window for replay.

  • EXF-0002Side-Channel ExfiltrationST0008
    addresses
    moderate
    direct

    Side-channel exfiltration parent (primary: Art. 85(1)) cascades to 85(2) — key rotation discipline limits the value of side-channel-recovered keys.

  • EXF-0002.01Power Analysis AttacksST0008
    addresses
    moderate
    direct

    Power-analysis attacks (primary: Art. 85(1)) cascade to 85(2) — key rotation cadence limits how many traces an attacker can amass against a single key.

  • EXF-0002.02Electromagnetic Leakage AttacksST0008
    addresses
    moderate
    direct

    EM-leakage attacks (primary: Art. 85(1)) cascade to 85(2) — key rotation limits exposure window.

  • EXF-0002.04Timing AttacksST0008
    addresses
    moderate
    direct

    Timing attacks (primary: Art. 85(1)) cascade to 85(2) — periodic key rotation limits the window for statistical timing recovery.

  • EXF-0003Signal InterceptionST0008
    addresses
    moderate
    direct

    Signal interception (primary: Art. 85(1)/(3)) is mitigated by 85(2)'s key rotation — limiting the operational window in which intercepted material can be decrypted.

  • EXF-0003.01Uplink ExfiltrationST0008
    addresses
    moderate
    direct

    Uplink interception (primary: Art. 85(1)/(3)) is mitigated by 85(2)'s key lifecycle — counter and key rotation discipline limits replay/clone potential of captured material.

  • EXF-0003.02Downlink ExfiltrationST0008
    addresses
    moderate
    direct

    Downlink exfiltration (primary: Art. 85(1)) is mitigated by 85(2)'s key rotation — limiting how much intercepted downlink content remains decryptable per key.

  • EXF-0005Proximity OperationsST0008
    addresses
    moderate
    direct

    Proximity TEMPEST/EMSEC exfiltration (primary: Art. 85(1)) cascades to 85(2) — key lifecycle discipline limits exposure window from proximity capture.

  • EXF-0009Compromised Partner SiteST0008
    addresses
    moderate
    direct

    Compromised-partner exfiltration (primary: Art. 85(1)) is mitigated by 85(2) — partner-segment key rotation limits cross-organization compromise impact.

  • IA-0001.02Software Supply ChainST0003
    addresses
    moderate
    direct

    Use of stolen signing keys to issue malicious patches directly attacks the cryptographic-key lifecycle 85(2) places on the operator — secure generation, storage, and distribution disciplines limit signing-key exposure.

  • IA-0002Compromise Software Defined RadioST0003
    addresses
    moderate
    direct

    SDR compromise (primary: Art. 85(1)) cascades to 85(2) — when SDR compromise touches crypto material, key lifecycle discipline (signed waveform updates, rotation) is the operator-side control.

  • IA-0003Crosslink via Compromised NeighborST0003
    addresses
    moderate
    direct

    Crosslink-via-compromised-neighbor (primary: Art. 85(1)/(3)) cascades to 85(2) — crosslink key lifecycle limits the window during which a compromised neighbor's keys remain valid.

  • IA-0005.01Compromise EmanationsST0003
    addresses
    low
    inferred

    Art. 85(2)'s key-lifecycle policy is crypto-domain-relevant to compromise-emanations, but limits leaked-key value rather than interdicting the side-channel extraction; physical shielding and power masking are the actual mitigation (the Sprint D IA-0005.01 call).

  • IA-0007.01Compromise On-Orbit UpdateST0003
    addresses
    high
    direct

    On-orbit-update pipeline compromise (primary: Art. 85(1) signed updates) cascades to 85(2) — signing-key lifecycle is the operator-side discipline that limits malicious-update insertion.

  • IA-0008Rogue External EntityST0003
    addresses
    moderate
    direct

    Rogue-external-entity (primary: Art. 85(3)) cascades to 85(2) — proper key lifecycle ensures only authorized identities hold valid keys.

  • IA-0008.01Rogue Ground StationST0003
    addresses
    moderate
    direct

    Rogue ground station (primary: Art. 85(3)) cascades to 85(2) — key-lifecycle discipline ensures rogue stations cannot acquire valid keys through stale or improperly disposed material.

  • IA-0008.02Rogue SpacecraftST0003
    addresses
    moderate
    direct

    Rogue spacecraft (primary: Art. 85(1)) cascades to 85(2) — crosslink/proximity key lifecycle limits rogue-vehicle ability to present valid credentials.

  • PER-0004Replace Cryptographic KeysST0005
    addresses
    high
    direct

    Replacing cryptographic keys directly attacks the lifecycle 85(2) places on the operator — secure generation, storage, distribution, and disposal disciplines must include controls on rekey command authorization itself.

  • RD-0003.02Cryptographic KeysST0002
    addresses
    high
    direct

    Cryptographic-key acquisition from operator-controlled sources (compromised ground systems, repositories, contractor channels) directly attacks the lifecycle 85(2) places on the operator — generation, use, storage, distribution, and disposal disciplines limit key exposure.

  • REC-0001.03Cryptographic AlgorithmsST0001
    addresses
    high
    direct

    85(2)'s cryptographic-key lifecycle policy governs the protection of key types and lifecycles that REC-0001.03 reconnaissance seeks to enumerate.

  • REC-0003.04Valid CredentialsST0001
    addresses
    high
    direct

    Cryptographic-key acquisition by adversaries directly attacks the lifecycle (generation, use, storage, distribution, disposal) that 85(2) places on the operator.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.