Annex 3.2.1
Mapped SPARTA techniques (52)
Techniques referencing this article
Monitoring-and-logging procedures must surface FDIR-disable events, watchdog-timeout extensions and limit-threshold widenings, which are the observable signatures of fault-management suppression.
Monitoring-and-logging procedures must surface telemetry gaps and abnormal display-pipeline behaviour, which are the observable signatures of downlink disruption or deception.
Monitoring-and-logging procedures must capture telemetry-processing pipeline anomalies, gaps and unexpected configuration changes that signal ground-system inhibition.
Monitoring-and-logging procedures must surface link-margin degradation and noise-floor excursions on the downlink, which are the observable signatures of jamming used as evasion.
Monitoring-and-logging procedures must surface telemetry-source quieting, packet-rate drops and event-channel muting, which are the observable signatures of source-side telemetry suppression.
Monitoring-and-logging must surface counter freezes, mode-flag inconsistencies and crypto-state divergences across redundant telemetry paths, which are the observable signatures of on-board-value obfuscation.
Monitoring procedures must capture VCC values, increment cadence and divergences from per-pass expected counts; this is the principal observable signature of VCC tampering.
Monitoring procedures must capture rejected-command-counter drops, sudden zeroing and disagreement with command-history audit trails as observable signatures of evasion.
Monitoring procedures must surface receiver-state changes that create deliberate quiet windows, which are observable from telemetry transitions and pass-coverage gaps.
Monitoring-and-logging procedures should capture AGC and lock-state telemetry trends to surface anomalous receiver behaviour configured to silently reject legitimate signals.
Monitoring-and-logging procedures must capture command-lock-state transitions, frame-lock anomalies and partial-acquisition telemetry, which are the observable signatures the adversary uses for geometry validation and quiet-window selection.
Monitoring-and-logging procedures should detect telemetry-mode transitions and per-VC/APID drop-outs that create selective evasion windows.
Monitoring-and-logging procedures must surface crypto-state transitions (algorithm changes, key-set switches, encryption-off states) as high-severity logging events.
Monitoring procedures must surface PNT-solution anomalies (impossible jumps, cross-source disagreements with onboard ephemeris) that signal GPS-ephemeris spoofing.
Monitoring-and-logging procedures should capture WDT-configuration changes, reset-policy modifications and unusual reset cadences that signal evidence shaping.
Monitoring-and-logging must run continuously across mode transitions; safe-mode is precisely where reduced visibility creates the protection-subversion opportunity, and the implementing regulation does not exempt it.
Monitoring-and-logging procedures must surface inconsistencies between system-state reports and authoritative sources (resource consumption, watchdog timing, redundant telemetry), which are the observable signatures rootkits attempt to hide.
Monitoring-and-logging procedures should surface SDA-feed anomalies, catalog-update inconsistencies and sensor-correlation drop-outs that signal SDA-pipeline compromise or spoofing.
Monitoring-and-logging procedures must surface anomalous-but-credentialed activity (off-hours operator actions, geographic anomalies, command-pattern deviations) that signal evasion via valid credentials.
Monitoring-and-logging procedures must surface duplicate or out-of-sequence command/data events; replay attempts are observable in command counters and audit trails.
Command-side monitoring must detect duplicate frames and counter regressions, which are the observable signatures of command-packet replay.
Monitoring procedures must surface anomalous activation events keyed to orbital state; correlation between attitude/ephemeris transitions and unexpected behaviour is the observable signature of geofenced triggers.
Monitoring-and-logging must surface encryption state changes; transitions to weaker or disabled crypto on TT&C or storage paths are observable and high-severity logging events.
Monitoring procedures should surface anomalous activations correlated with absolute timestamps and shared time-source events.
Monitoring should correlate anomalous behaviour with prior reset/safing/comm-pattern events that match relative-time-trigger latch points.
Monitoring-and-logging procedures must surface anomalous system-state reporting and detect tampering with telemetry pipelines, which is the principal observable signature of rootkit presence.
Monitoring-and-logging procedures must run continuously across mode transitions; the implementing regulation does not exempt safe-mode windows from log retention and review.
Monitoring-and-logging must surface parameter changes and anomalous on-board-value modifications; this is the detective control for unauthorized modification.
Monitoring-and-logging procedures must capture memory-write commands and post-effect telemetry, which are the observable signatures of malicious memory loading.
Monitoring-and-logging procedures must surface parameter modifications to safety-critical subsystems like propulsion before mission-affecting effects materialize.
Monitoring-and-logging procedures must capture WDT-configuration changes and reset-policy modifications, which are subtle observable signatures of liveness-supervision tampering.
Monitoring-and-logging procedures must surface anomalous traffic volume, command rates and parser-load events, which are the observable signatures of flooding attacks.
Monitoring-and-logging procedures must surface elevated valid-command rates and unusual operator command-history patterns, which are the observable signatures of valid-command flooding.
Monitoring-and-logging procedures must surface inputs that violate authenticator expectations, time/sequence consistency or sensor-fusion bounds — the observable signatures of spoofing.
Monitoring-and-logging procedures must surface PNT-solution anomalies (impossible jumps, cross-source disagreements) that signal spoofing.
Monitoring-and-logging procedures must surface link-margin degradation and noise-floor excursions, which are the observable signatures of jamming.
Monitoring procedures must capture uplink-margin reduction and acquisition failures, which are the observable signatures of uplink jamming.
Monitoring procedures must surface degraded user-segment SNR, beam-blockage patterns and downlink-availability anomalies that signal jamming.
Monitoring-and-logging procedures must surface duplicate or unauthorized-source command sequences that solicit recorder playbacks or bulk dumps, which is the observable signature of replay-driven exfiltration.
Monitoring-and-logging procedures must cover sparsely-supervised secondary links (beacons, rekeying paths, contingency profiles); the implementing regulation does not exempt low-rate housekeeping channels from log retention and review.
Monitoring-and-logging procedures must surface link-configuration changes, anomalous sidebands and unexpected emissions toward non-mission receivers, which are the observable signatures of communications-config exfiltration.
Monitoring procedures should surface transponder configuration changes and anomalous routing-table updates that signal transponder misuse for covert exfiltration.
Monitoring-and-logging procedures must surface anomalous bulk-export activity, recorder-playback scraping and unusual cross-site link traffic, which are the observable signatures of compromised-ground-system exfiltration.
Monitoring-and-logging procedures must cover backup paths because they are precisely the channels less frequently exercised and most likely to harbour unnoticed adversary presence.
Monitoring-and-logging on standby MOC sites and reserve operator workstations must run continuously; the implementing regulation does not exempt seldom-used systems from log retention and review.
Monitoring-and-logging procedures on operator workstations, mission-control servers and gateway equipment are the detective control that surfaces a ground-system intrusion before commanding effects occur.
Monitoring-and-logging procedures must surface anomalous command sequences on otherwise legitimate operator workstations; this is the detective control for valid-GS-misuse.
Monitoring-and-logging procedures must run continuously, including during safe-mode windows; the implementing regulation does not exempt reduced-payload or contingency operating regimes from log retention and review.
Monitoring-and-logging procedures must surface telemetry inconsistencies, cross-source disagreements and anomalous source patterns that signal deception or misdirection.
Monitoring-and-logging procedures are the principal detective control for ground-system persistence; long-dwell attacker behaviour leaves observable signatures across operator workstations, auth servers and gateway equipment.
Monitoring-and-logging procedures are the detective control that surfaces a compromised mission-operated GS as adversary infrastructure before it is used for mission-impact actions.
Active scanning is observable: the entity's monitoring-and-logging procedures must surface anomalous probe responses, frequency-sweep correlation and TT&C link-margin changes that signal an adversary scan.