All techniques
EX-0012.10
ST0004Execution
sub-technique

Command & Data Handling Subsystem

Parent: EX-0012

Description

C&DH relies on tables and runtime values that define how commands are parsed, queued, and dispatched and how telemetry is collected, stored, and forwarded. Targets include opcode-to-handler maps, argument limits and schemas, queue depths and priorities, message ID routing, publish/subscribe bindings, timeline/schedule entries, file catalog indices, compression and packetization settings, and event/telemetry filters. Edits to these artifacts reshape control and visibility: commands are delayed, dropped, or misrouted; telemetry is suppressed or redirected; timelines slip; and housekeeping/data products are repackaged in ways that confuse ground processing. Because many frameworks treat these values as authoritative configuration, small changes can silently propagate across subsystems, degrading responsiveness, creating backlogs, or severing the logical pathways that keep the vehicle coordinated, without modifying the underlying code.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    moderate
    derived

    Authentication bounds who can alter C&DH configuration that governs command parsing and dispatch.

  • craAnnex I, Part I, (2)(f)
    addresses
    high
    derived

    Integrity protection on C&DH tables and runtime values (opcode-to-handler maps, queue policies) is essential to command correctness.

  • eu-space-actArt. 81(3)
    addresses
    high
    direct

    C&DH tables (opcode-to-handler maps, queue depths, message ID routing) are core control-flow configuration — 81(3)(b)'s critical-function restriction governs who can modify these.

  • eu-space-actArt. 84(2)
    addresses
    high
    direct

    C&DH is the canonical mission network-and-information-system; 84(2)'s Annex VII point 5.1 compliance includes integrity on dispatch/route configuration.

  • nis2Art. 21(2)(b)
    addresses
    moderate
    derived

    Telemetry suppression, command queue manipulation, and silent housekeeping repackaging are detectable as integrity incidents; Art. 21(2)(b)'s incident-handling capability must surface them via configuration-integrity baselines.

  • nis2Art. 21(2)(i)
    addresses
    moderate
    direct

    Opcode-to-handler maps, argument schemas, queue depths, message-ID routing, pub/sub bindings, and timeline entries are precisely the access-controlled C&DH configuration Art. 21(2)(i)'s access-control + asset-management obligation governs.

  • nis2-implAnnex 6.3.1
    addresses
    moderate
    derived

    Configuration-management obligations cover C&DH-runtime tables as part of the documented configuration baseline subject to deviation detection.

  • nis2-implAnnex 6.4.1
    addresses
    moderate
    derived

    C&DH tables and runtime values (opcode-to-handler maps, queue policies, telemetry collection lists) are change-managed configuration; modifications go through documented release and emergency-change procedures.

ENISA controls

  • Criticality analysis identifies C&DH as a mission-critical subsystem and prioritises it for protective controls, governing where integrity and access measures apply rather than itself defending against table modification.

  • Configuration management of the C&DH baseline detects unauthorised modifications EX-0012.10 makes.

  • Process-ID whitelisting on the satellite bus is the canonical defense against unauthorised C&DH modifications.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EX-0012.10 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.