All techniques
IA-0004.01
ST0003Initial Access
sub-technique

Ground Station

Parent: IA-0004

Description

Threat actors may target the backup ground segment, standby MOC sites, alternate commercial stations, or contingency chains held in reserve. Threat actors establish presence on the backup path (operator accounts, scheduler/orchestration, modem profiles, antenna control) and then exploit moments when operations shift: planned exercises, maintenance at the primary site, weather diversions, or failover during anomalies. They may also shape conditions so traffic is re-routed, e.g., by saturating the primary’s RF front end or consuming its schedules, without revealing their involvement. Once on the backup, prepositioned procedures, macros, or configuration sets allow command injection, manipulation of pass timelines, or quiet collection of downlink telemetry.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    high
    derived

    Authentication obligations apply equally on backup ground-station infrastructure; products must enforce equivalent auth on contingency commanding paths.

  • eu-space-actArt. 81(1)
    addresses
    high
    direct

    Backup ground-station accounts, scheduler/orchestration access, and antenna control are governed by 81(1)'s identity-and-access-management protocols — the same IAM discipline applies to the standby site as to the primary.

  • eu-space-actArt. 81(4)
    addresses
    moderate
    direct

    Backup-ground-station compromise (primary: Art. 81(1)) cascades to 81(4) — credential audit on standby-site accounts is part of lifecycle discipline.

  • eu-space-actArt. 92(1)
    addresses
    moderate
    direct

    Alternate commercial stations and contingency chains are supplier relationships under 92(1) — operator contracts must include information-security requirements for backup providers.

  • nis2Art. 21(2)(c)
    addresses
    high
    direct

    Backup ground operations and the processes that shift traffic to the standby site (planned exercises, weather diversions, anomaly failover) are the precise scope of business continuity, backup management, and disaster recovery under Art. 21(2)(c).

  • nis2Art. 21(2)(d)
    addresses
    high
    direct

    Standby commercial stations and contingency-chain operators are direct service providers; Art. 21(2)(d)'s supplier-relationship security obligation governs the trust framework around backup-path operator accounts, scheduler/orchestration, and modem profiles.

  • nis2Art. 21(2)(j)
    mitigates
    moderate
    direct

    Multi-factor authentication on backup-station operator accounts and scheduler portals under Art. 21(2)(j) blocks the credential path through which adversaries establish presence on the standby ground segment ahead of failover.

  • nis2Art. 21(3)
    addresses
    high
    derived

    Primary mapping to Art. 21(2)(d) covers the commercial ground-station-as-a-service supplier. Art. 21(3) procedurally extends to assessment of that supplier's secure-operations and vulnerability-handling practices, the lever the operator uses to enforce cybersecurity quality on the GSaaS provider.

  • nis2-implAnnex 11.7.1
    addresses
    high
    derived

    Multi-factor authentication is required on commanding paths; backup-ground-station operator stations and contingency commercial-station gateways must enforce MFA at the same strength as the primary site.

  • nis2-implAnnex 3.2.1
    addresses
    high
    derived

    Monitoring-and-logging on standby MOC sites and reserve operator workstations must run continuously; the implementing regulation does not exempt seldom-used systems from log retention and review.

  • nis2-implAnnex 5.1.1
    addresses
    moderate
    derived

    Alternate commercial ground stations held in reserve are direct suppliers under the supply-chain policy; the policy's verification and contractual obligations apply to them irrespective of their reserve status.

ENISA controls

  • Access control with least privilege and four-eyes principle on the backup MOC and contingency stations defeats the foothold IA-0004.01 establishes there.

  • Multi-factor authentication on backup-site operator accounts limits credential-only compromise of the standby ground segment.

  • Intrusion detection and prevention covering backup ground systems surfaces the establishment of presence on standby chains before they activate.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, IA-0004.01 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.