Annex 6.8.1
Mapped SPARTA techniques (18)
Techniques referencing this article
Segmentation between bus segments (and between the bus and crosslink/payload-facing functions) bounds where replayed bus traffic can travel and which subsystems it reaches.
Network segmentation defines the trust boundaries that internal routing tables enforce; segmentation discipline constrains the scope of damage from a routing-table rewrite.
Bus segmentation between high-trust and low-trust subsystems bounds where forged bus frames can travel and which subscribers consume them.
Network segmentation between hosted payload and host-bus subsystems is the architectural control that prevents host-bus data from being routed into payload-side communications channels for covert exfiltration.
Network segmentation between crosslink-facing and bus-internal subsystems is the architectural defense that prevents a compromise on a neighboring vehicle from being a bridgehead onto the local spacecraft.
Network segmentation between hosted payload and host-bus subsystems is the architectural control that prevents payload-to-bus pivot; the implementing regulation requires segmentation based on risk-assessment-driven trust boundaries.
Network segmentation isolates operator workstations, mission-control servers, baseband chains and archive databases from each other and from corporate IT, so that one foothold does not yield ground-segment-wide command authority.
Segmentation between crosslink-facing functions and bus internals is the architectural lever that bounds what a rogue-spacecraft peer can reach even if it briefly occupies the RF geometry.
Segmentation between user-segment networks and core mission systems is the architectural defense that prevents user-segment compromise from reaching commanding or telemetry-distribution backends.
Segmentation between hosted payload and host-bus subsystems is the architectural control that bounds the host's reach into the payload — the inverse direction of IA-0006 but the same segmentation discipline.
Network segmentation between hosted payload and host-bus subsystems is the architectural control that blocks payload-to-bus pivot via SpaceWire/1553/Ethernet gateways and shared file services.
Lack of bus segregation is precisely the architectural deficiency the network-segmentation obligation is established to remedy: the implementing regulation requires segmentation based on risk-assessment-driven trust boundaries.
Segmentation between crosslink-facing functions and bus internals is the architectural defense that bounds how far a compromise on one constellation member can travel via inter-satellite links.
Segmentation between docking/berthing interfaces and main-bus subsystems is the architectural control that bounds the reach of a compromised visiting vehicle.
Segmentation between launch-vehicle EGSE networks and operator/payload networks bounds the reach of a launch-side compromise into the entity's mission systems.
Network segmentation between rideshare payloads (data buses, deployer controllers, telemetry collectors) is the architectural control that the implementing regulation requires to prevent inter-payload pivot before separation.
Network segmentation isolates persistent footholds from spreading across the ground segment; segmentation discipline limits the spacecraft-reachability of an attacker established on a single workstation.
Network segmentation is the precise architectural control that limits lateral mobility inside a compromised mission-operated ground system; the implementing regulation requires the entity to segment systems into networks or zones based on risk assessment.