Annex 6.4.1
Mapped SPARTA techniques (44)
Techniques referencing this article
FDIR/safing logic, watchdog parameters and limit/sanity-check thresholds are change-managed configuration; documented change procedures detect and block unauthorized disabling of fault management.
On-board telemetry-publisher state, packet filters, rates and channel mute settings are change-managed configuration; documented procedures govern modification of these settings whether commanded or implanted.
Housekeeping counters, severity flags, mode selectors and crypto-state indicators are change-managed values; documented change procedures detect unauthorized obfuscation of these operator-visible truths.
VCC value alterations and command-path bypasses are change-management events governed by the implementing regulation's change-control procedures.
Modifications to the rejected-command counter or its downlink representation are change-management events that must follow documented procedures.
Toggling receiver enable states is a change-management event; documented procedures must govern configuration of receiver power and band selection.
Modifications to receiver AGC and signal-strength thresholds are change-managed configuration; documented procedures govern their alteration to prevent receivers from being detuned to refuse legitimate command traffic.
Configuration changes that alter receiver lock-state reporting (telemetry packet contents, severity flags) are change-management events governed by documented procedures.
Telemetry-mode switches, virtual-channel maps and APID selections are change-managed configuration; their modification follows documented procedures with review for mission-impact.
Cryptographic mode changes are change-management events with significant security consequences; documented procedures with review and authorization govern such transitions.
Clock writes and time-discipline source changes are change-management events with significant downstream effects; documented procedures must govern such modifications.
WDT parameter modification (timeouts, pet-task assignment) is change-managed configuration; documented procedures govern such modifications because their evidence-shaping effects are significant.
Safe-mode profiles, contingency dictionaries and relaxed-check parameters are change-managed configuration; documented procedures must govern their definition and ensure the entry/exit transitions do not become evasion windows.
Whitelist-table modifications are change-management events; documented procedures must govern additions, removals and edits of whitelisted process/program identifiers.
Boot-chain modification is change-managed; documented change procedures detect unauthorized alteration of boot ROM, early loaders and device-tree initialization.
Change-management procedures govern modifications to flight or ground authentication services; they are the procedural envelope that detects and blocks unauthorized auth-process alteration.
Boot ROM, bootloader configuration and early-init code are managed under change-management procedures; the implementing regulation requires the entity to control modifications to these crown-jewel components.
Change-management procedures govern when and how hardware-level commands are issued in production; out-of-procedure issuance is exactly what an attacker exploits.
Cryptographic configuration changes (encryption-on/off toggles, suite downgrades, key-rotation overrides) are change-management events that must follow documented procedures with review and authorization.
Change-management procedures govern modifications to flight-software processes, OS components and FSW frameworks; rootkit installation requires subverting that change pipeline.
Boot-chain artefacts (boot ROM, bootloader, init code) are managed under change-management procedures; the implementing regulation requires the entity to control modifications to these crown-jewel components and bootkit installation must subvert that pipeline.
Modifications to live or persistent on-board values (registers, parameter tables, routing maps) are change-management events; the implementing regulation requires the entity to control changes to network-and-information-system parameters under documented procedures.
Register-level changes are change-management events; the implementing regulation requires controlled modification through documented procedures with review and authorization.
Internal routing-table rewrites are configuration changes governed by change-management procedures; the implementing regulation requires controlled modification with documented review.
Direct memory-write/load operations are change-management events that must follow documented procedures; emergency procedures still require documentation and post-event review.
App/subscriber table modifications are configuration changes; change-management procedures govern release, modification and emergency edits to these tables.
Scheduling-algorithm parameters (priorities, periods, deadlines) are change-managed configuration; modifications must follow documented procedures with review and rollback paths.
Propulsion parameters (thruster calibration, valve timing, safing thresholds) are change-managed configuration; alterations must follow documented procedures and be reviewed for their mission impact.
ADCS parameters (star-tracker catalogs, sensor alignments, gyro biases, estimator covariances) are change-managed configuration; modifications must flow through documented procedures.
EPS parameters (bus voltage limits, charge curves, load-shed priorities) are change-managed configuration whose modifications must follow documented procedures with risk-assessment-driven review.
C&DH tables and runtime values (opcode-to-handler maps, queue policies, telemetry collection lists) are change-managed configuration; modifications go through documented release and emergency-change procedures.
Watchdog-timer parameters (timeouts, reset actions, windowed bounds) are change-managed configuration; alterations must follow documented procedures because their mission-safety impact is significant.
Clock writes and time-base reconfiguration are change-management events with significant downstream effects on sequencing, anti-replay and navigation; documented procedures must govern such modifications.
Out-of-band link configuration changes (vendor/service modes, contingency profiles, beacon-content edits) are change-management events; documented procedures govern the activation and modification of these secondary paths.
Communications-configuration alterations (carrier retuning, sidebands, modulation/coding profiles, virtual-channel/APID remaps, beacon content, regenerative-payload routing tables) are change-management events that must follow documented procedures with review and rollback paths.
SDR firmware and waveform-profile changes are change-management events; documented procedures govern release, modification and emergency edits to these reconfigurable radios.
Transponder configuration changes (input–output remap, translation-frequency shifts, polarization and gain edits, regenerative routing tables) are change-management events that must follow documented procedures.
Change-management procedures govern how SDR firmware, profiles and bitstreams are altered, reviewed and pushed to flight or ground SDRs — the procedural envelope an SDR-compromise adversary must subvert.
Change-management procedures govern when backup receivers are enabled, reconfigured or cross-strapped, which are precisely the moments adversary access via the alternate path is most likely.
On-orbit update production is a change-management process; the implementing regulation requires the entity to apply documented procedures to control changes, including releases, modifications and emergency builds for flight software, configuration tables and ephemerides.
Change-management procedures govern flight-software, configuration table and parameter pushes during AIT and last-minute pad-side updates; ATLO compromises ride exactly that change pipeline.
Unauthorized parameter changes that drive accelerated subsystem aging (over-charging batteries, repeated thermal cycling, propellant-budget waste) are change-management events; documented procedures must govern such modifications and surface anomalous patterns.
Memory-compromise persistence requires modifying boot ROM handoff vectors, first-stage code and initialization paths — all change-management-controlled artefacts under the implementing regulation's procedures.
Cryptographic-key replacement is a change-management event with dramatic security consequences; documented procedures with separation-of-duty review are the implementing-regulation lever that prevents single-operator key replacement under attacker direction.