All techniques
EX-0012.06
ST0004Execution
sub-technique

Science/Payload Data

Parent: EX-0012

Description

Payload data, and the metadata that gives it meaning, can be altered in place to steal value, mislead users, or degrade mission outputs. Targets include raw detector frames, packetized Level-0 streams, onboard preprocessed products, and file catalogs/directories on mass memory. Adjacent metadata such as timestamps, pointing/attitude tags, calibration coefficients, compression settings, and quality flags are equally potent; slight bias in a calibration table or time tag can skew entire downlink campaigns while appearing routine. An adversary may rewrite frame headers, reorder packets, substitute segments from prior passes, or flip quality bits so ground pipelines silently discard or misclassify products. Recorder index manipulation can orphan files or cause downlinks to serve stale or fabricated content. Because many missions perform some processing or filtering onboard, tampering upstream of downlink propagates forward as “authoritative” truth, jeopardizing mission objectives without obvious protocol anomalies.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(e)
    addresses
    moderate
    derived

    The article requires encrypting stored and processed data such as the raw frames, Level-0 streams, calibration tables, and time tags this technique targets in place on mass memory and onboard, and encryption at rest denies an adversary the readable plaintext needed to make the meaningful biased rewrites the technique relies on. It only addresses the technique because the excerpt mandates confidentiality protection and does not require detecting or rejecting alterations to the data itself.

  • craAnnex I, Part I, (2)(f)
    addresses
    high
    derived

    Integrity protection on stored or transmitted data covers payload products, raw frames, Level-0 streams and metadata against in-place modification.

  • eu-space-actArt. 80(3)
    addresses
    moderate
    direct

    Payload data and metadata (timestamps, calibration coefficients, quality flags) require 80(3)'s integrity categorization — the rationale clause 'the need to ensure the confidentiality, integrity, authenticity and availability of information' explicitly extends to data products.

  • eu-space-actArt. 84(2)
    addresses
    moderate
    inferred

    Art. 84(2)'s comply-with-Annex-VII-5.1 reference is domain-relevant to payload-data modification, but the cited text names no specific interdicting mechanism; integrity protection (signing) of the data would be the interdiction.

  • nis2Art. 21(2)(h)
    addresses
    moderate
    inferred

    Integrity-protected payload products and signed metadata detect in-place upstream tampering, but they do not prevent onboard tampering by an adversary with write access, where the operative control is data integrity and access control rather than communications cryptography. Under the strict bar the cryptographic control detects tampering but does not interdict the defining onboard vector, so at NIS2 Art. 21(2)(h) the relationship is addresses.

  • nis2Art. 21(2)(i)
    addresses
    moderate
    direct

    Mass-memory file catalogs, recorder indices, and Level-0 stream stores are access-controlled assets; Art. 21(2)(i)'s access-control + asset-management obligation governs who can rewrite frame headers, reorder packets, or substitute segments.

  • nis2-implAnnex 12.1.1
    addresses
    moderate
    derived

    Payload data, raw frames, Level-0 streams and metadata are mission-critical information assets whose classification level governs handling and integrity controls; in-place modification is precisely the leakage/integrity threat classification protects against.

  • nis2-implAnnex 12.2.1
    addresses
    moderate
    derived

    Asset-handling policy governs how payload products are stored, transported and disseminated, which is the procedural envelope around in-place modification of science/payload outputs.

ENISA controls

  • Data management procedures cover handling and protection of payload and science data, the assets EX-0012.06 modifies.

  • Integrity checks on payload and science data products detect modification of the values EX-0012.06 alters in storage.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EX-0012.06 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.