eu-space-act

Art. 88(1)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (20)

Techniques referencing this article

  • DE-0003.12Poison AI/ML Training for EvasionST0006
    addresses
    moderate
    direct

    88(1)'s testing programme can include adversarial-input testing on monitoring models — surfacing clean-label backdoors and biased-sampling artifacts.

  • DE-0007Evasion via RootkitST0006
    addresses
    moderate
    direct

    Rootkit detection requires offline integrity attestation, image hashing, and kernel-introspection testing — within 88(1)'s testing programme scope.

  • 88(1)'s testing programme and 88(3)'s Threat Led Penetration Testing can include behavioral testing across the orbital trajectory — surfacing geofenced triggers that fire only at specific positions or times.

  • EX-0005.01Design FlawsST0004
    addresses
    moderate
    direct

    88(1)'s testing programme can include hardware-design fuzzing, scan-chain testing, and FPGA partial-reconfig validation — surfacing the design-flaw classes EX-0005.01 enumerates.

  • EX-0009Exploit Code FlawsST0004
    addresses
    high
    direct

    88(1)'s testing programme, with 88(3)'s 3-yearly Threat Led Penetration Testing, is the operator's discipline that surfaces software defects before adversaries find them.

  • EX-0009.01Flight SoftwareST0004
    addresses
    high
    direct

    88(1)'s testing programme, with 88(3)'s 3-yearly TLPT, is the operator discipline that surfaces FSW parser, command-handler, and table-loader defects before adversaries find them.

  • EX-0009.02Operating SystemST0004
    addresses
    high
    direct

    OS-level testing (kernel fuzzing, syscall fuzzing, privilege boundary validation) is part of the testing programme 88(1) requires.

  • EX-0010Malicious CodeST0004
    addresses
    moderate
    direct

    88(1)'s testing programme, including TLPT, validates that legitimate update/file-transfer/maintenance pathways do not accept malicious payloads.

  • EX-0010.03RootkitST0004
    addresses
    moderate
    direct

    Regular tests under 88(1) — including out-of-band integrity attestation and offline image verification — surface rootkit-induced discrepancies that runtime telemetry alone hides.

  • EX-0012.13Poison AI/ML Training DataST0004
    addresses
    moderate
    direct

    88(1)'s testing programme can include adversarial-input testing and model-validation against poisoned-corpus scenarios — surfacing clean-label backdoors and decision-boundary skew.

  • EX-0015Side-Channel AttackST0004
    addresses
    moderate
    direct

    88(1)'s testing programme can include side-channel and fault-injection testing during integration — surfacing leakage and glitch susceptibility.

  • EXF-0002Side-Channel ExfiltrationST0008
    addresses
    moderate
    direct

    88(1)'s testing programme can include side-channel and fault-injection testing — surfacing leakage and glitch susceptibility in operator products.

  • EXF-0008Compromised Developer SiteST0008
    addresses
    moderate
    direct

    88(1)'s testing programme should extend to test harnesses, simulators, and flight builds — verifying that compromised dev artifacts cannot reach production silently.

  • 88(1)'s testing programme obligation can include supply-chain integrity checks (e.g., verification of dependency provenance, signed-build validation) that detect dependency-confusion or build-poisoning attempts before deployment.

  • LM-0005Virtualization EscapeST0007
    addresses
    moderate
    direct

    Hypervisor/separation-kernel boundary testing — fuzzing of message ports, IOMMU validation — is within 88(1)'s testing programme scope.

  • PER-0002BackdoorST0005
    addresses
    moderate
    direct

    Backdoors are detected through testing — 88(1)'s testing programme, including 88(3)'s 3-yearly Threat Led Penetration Testing, is the operator discipline that surfaces hidden command handlers and undocumented service modes.

  • PER-0002.01Hardware BackdoorST0005
    addresses
    moderate
    direct

    Hardware-backdoor detection requires test/scan-chain validation, fuse-state checks, and reverse engineering — within 88(1)'s testing programme scope.

  • PER-0002.02Software BackdoorST0005
    addresses
    high
    direct

    Software backdoors hide in code paths the testing programme under 88(1) is meant to surface — code review, fuzzing, and TLPT under 88(3) are the operator-side disciplines.

  • REC-0006.02Security Testing ToolsST0001
    addresses
    moderate
    direct

    Reconnaissance of the operator's testing programme (static analyzers, fuzzers, formal-methods coverage) discloses test gaps; 88(1)'s testing programme obligation places operator responsibility on what is tested and how.

  • REC-0008.03Known VulnerabilitiesST0001
    addresses
    moderate
    direct

    88(1)'s testing programme obligation, including (88)(3)'s 3-yearly Threat Led Penetration Testing, validates that the operator's products are tested against known-vulnerability catalogs.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.