Annex 11.2.1
Mapped SPARTA techniques (17)
Techniques referencing this article
Access-rights provisioning across the host–payload boundary is the operational lever that bounds whether payload code can read bus telemetry or host-bus data for embedding in payload products.
Access-rights provisioning between hosted payload and host bus is the operational lever that limits which payload commands the bus accepts and which bus telemetry the payload can read.
Access-rights provisioning to third-party connections must follow the same provision-modify-remove discipline as internal accounts; trusted-relationship abuse is the consequence of stale or over-broad third-party rights.
Access-rights to data portals, shared repositories and federated identity systems must be provisioned, modified and removed under documented procedures that match collaborator role tenure.
Access-rights to tasking portals, customer gateways and downstream processing pipelines must be provisioned and revoked under documented procedures; over-broad user-segment access is the enabler of this technique.
Access-rights provisioning bounds the population that can read or copy mission-critical datasets; over-broad access is the leverage data-theft attacks exploit.
Access-rights provisioning across the host–payload boundary is the operational lever that bounds which payload commands reach the bus and which bus telemetry the payload can read.
Access-rights hygiene under the provision/modify/remove obligations bounds the scope of credentialed traversal; over-broad operator and service-account rights are the leverage this technique exploits.
Access-rights provisioning hygiene (revocation on role change, periodic review) is the operational lever that bounds the dwell time of persistent attacker access to ground systems.
Provision, modification and removal of access rights under documented procedures is the operational lever that prevents stale credentials from carrying persistent access across role changes, project transitions and offboarding.
Provision, modification and removal of access rights is the operational mechanism that bounds an attacker's footprint inside compromised infrastructure; stale or over-broad rights are the leverage the technique exploits.
Access-rights provisioning hygiene at the mission-operated GS bounds the population the attacker can impersonate after foothold.
Provision, modification, removal and documentation of access rights to design repositories, ICD vaults, AIT records and contractor data rooms is the operational mechanism that prevents unauthorized retrieval of the engineering corpus the technique targets.
Access-rights provisioning to bus design repositories and AIT bus-test records is the operational mechanism that bounds who can extract bus topology information.
Access-rights provisioning to GNC simulators, control-design repositories and Monte-Carlo dispersion artefacts bounds who can reconstruct GNC behaviour from internal sources.
Access-rights provisioning to EPS modelling artefacts, fault-protection trees and autonomy thresholds bounds who can reconstruct power-related leverage points.
Access-rights to FTS architecture documentation must be tightly bounded; provisioning, modification and removal of those rights is the operational lever that limits FTS-recon exposure.