Art. 21(2)(j)
Mapped SPARTA techniques (22)
Techniques referencing this article
MFA/continuous authentication on operator tools and mission consoles under Art. 21(2)(j) defeats insider-credential masquerading at the ground-side end of the chain.
Multi-factor authentication or continuous authentication under Art. 21(2)(j) limits the value of valid-but-stolen credentials and forces session-binding signals that distinguish legitimate from credentialed-evasive use.
Mass-scale exfiltration via mission-control servers, modem chains, and archive databases depends on attacker credentials evading detection on operator/admin accounts; multi-factor or continuous authentication under Art. 21(2)(j) directly closes that gap.
Multi-factor authentication on developer-site identity providers, source-control accounts, and CI/CD orchestrators under Art. 21(2)(j) reduces the credential-driven entry path to the development environment the technique exploits.
Art. 21(2)(j) (MFA/secured comms within the entity) is domain-relevant to third-party access exposure but does not interdict this vector: mirroring mission data and MITM of partner-to-MOC links bypass any authenticated entity session. The operative control is secured-comms encryption of cross-org links, not MFA.
Multi-factor authentication on backup-station operator accounts and scheduler portals under Art. 21(2)(j) blocks the credential path through which adversaries establish presence on the standby ground segment ahead of failover.
Multi-factor authentication or continuous authentication under Art. 21(2)(j) defeats the credential-driven path through which most ground-segment compromises start (phishing, vendor-account theft, lateral IT-to-ops).
Continuous authentication or step-up MFA on operator sessions under Art. 21(2)(j) raises the bar against an attacker reusing a legitimate ground-segment session to insert procedures across multiple passes.
Scoped to its cyber authentication-defeat core, IA-0008 (a rogue external entity presenting mission-compatible traffic) triggers NIS2 Art. 21(2)(j): correct authentication of mission traffic rejects an origin that lacks valid credentials. The clearly physical strands of the technique (RF-geometry exploitation, directed-energy, and kinetic counterspace effects) fall outside the Article 21(2) cyber-risk measures and are excluded from this mapping. The jamming and spoofing electronic-warfare strand is not decided here; it is deferred to the E/F counterspace-scope determination, consistent with the IA-0008.03 hold.
IA-0008.02 succeeds when an impostor (rogue) spacecraft is honored on the inter-satellite link without valid credentials. NIS2 Art. 21(2)(j) governs the risk: correct authentication of the inter-satellite link rejects a peer presenting mission-compatible crosslink traffic but lacking valid keys. Orbital-geometry-aware anomaly detection is a compensating backstop, not the primary obligation.
Multi-factor authentication on partner integration accounts, jump hosts, and federated identities under Art. 21(2)(j) limits the value of credentials harvested from a compromised counterpart.
MFA on federated credentials and collaboration-portal accounts under Art. 21(2)(j) limits the value of any single compromised partner identity feeding configuration tables or commanding tools.
MFA on vendor remote-admin accounts, signing-tool sessions, and cross-account cloud roles under Art. 21(2)(j) reduces the credential-driven escalation path from vendor enterprise to mission infrastructure.
Continuous authentication and step-up MFA at enclave boundaries under Art. 21(2)(j) limit a single credential's reach by re-authenticating on cross-domain traversal — precisely the boundaries this technique abuses.
Continuous authentication and step-up MFA on operator/admin sessions under Art. 21(2)(j) are what limit a persistent attacker's ability to refresh tooling, queue commands across passes, and mirror legitimate operator behaviour.
Multi-factor authentication or continuous authentication under Art. 21(2)(j) defeats the 'operating with legitimate credentials' premise the technique relies on — even valid credentials become single-use without a second factor or session-binding signal.
Multi-factor authentication on customer accounts at commercial GS providers under Art. 21(2)(j) defeats the credential-purchase or weak-vetting routes through which adversaries co-opt legitimate scheduling and front-end configuration.
Multi-factor authentication or continuous authentication under Art. 21(2)(j) directly defeats the stolen-credential, exposed-remote-support, and lateral-IT-to-ops paths that drive most infrastructure compromise.
MFA on operator and admin accounts under Art. 21(2)(j) defeats the dominant phishing-and-pivot path through which mission-operated ground systems are compromised.
MFA on customer accounts at the third-party provider under Art. 21(2)(j) blocks the credential-driven misuse path the technique relies on for scheduling, front-end configuration, and data egress.
Multi-factor authentication or continuous authentication under Art. 21(2)(j) directly defeats reuse of credentials harvested from phishing, supply-chain compromise, repos, dumps, contractor laptops, or sanitised training data.
addresses; Art. 21(2)(j) is domain-relevant because developer-site IdPs, source-control, and CI/CD accounts should use MFA, but MFA does not interdict passive enumeration of the build environment, repo layouts, or secrets-in-configs; the operative control is the secure-development assurance of Art. 21(2)(e).