All techniques
IA-0009.01
ST0003Initial Access
sub-technique

Mission Collaborator (academia, international, etc.)

Parent: IA-0009

Description

Missions frequently depend on distributed teams, instrument builders at universities, science operations centers, and international partners, connected by data portals, shared repositories, and federated credentials. A compromise of a collaborator yields access to telescience networks, analysis pipelines, instrument commanding tools, and file exchanges that deliver ephemerides, calibration products, procedures, or configuration tables into mission workflows. Partners may operate their own ground elements or payload gateways under delegated authority, creating additional entry points whose authentication and logging differ from the prime’s. Initial access emerges when attacker-modified artifacts or commands traverse these sanctioned paths: a revised calibration script uploaded through a science portal, a configuration table promoted by a cross-org CI job, or a payload task submitted via a collaboration queue and forwarded by the prime as routine work. Variations in process rigor, identity proofing, and toolchains across institutions amplify the attacker’s options while preserving the appearance of legitimate partner activity.

Mappings

EU regulation articles

  • craAnnex I, Part II, (1)
    addresses
    moderate
    direct

    This technique abuses artifacts and components that collaborators deliver into mission workflows across institutions with differing toolchains, and the article requires identifying and documenting the vulnerabilities and components in products with digital elements, including a machine-readable software bill of materials covering at least top-level dependencies. That component and dependency documentation gives the prime visibility into which partner-supplied elements enter its products, which addresses the technique without blocking the injection path itself.

  • craArt. 13(5)
    addresses
    moderate
    derived

    Manufacturer due-diligence covers mission-collaborator integration via federated identity providers and shared data portals when those create dependencies on the product.

  • eu-space-actArt. 81(1)
    addresses
    moderate
    direct

    Federated credentials and delegated authority to collaborators must be governed by 81(1)'s IAM protocols — preventing collaborator-side compromise from cascading into mission enclaves.

  • eu-space-actArt. 81(4)
    addresses
    moderate
    direct

    Mission-collaborator compromise (primary: Art. 81(1)) cascades to 81(4) — federated-credential audit on partner accounts is the lifecycle discipline.

  • eu-space-actArt. 92(1)
    addresses
    high
    direct

    Mission collaborators (academic, international partners) operate under contractual or MoU relationships; 92(1)'s information-security contractual obligation extends to telescience and shared-repository connections.

  • nis2Art. 21(2)(d)
    addresses
    high
    direct

    Universities, science operations centres, and international partners with delegated authority over instrument commanding tools and data portals are direct service providers; Art. 21(2)(d)'s supplier-relationship security obligation governs the trust framework around those collaboration paths.

  • nis2Art. 21(2)(j)
    addresses
    moderate
    direct

    MFA on federated credentials and collaboration-portal accounts under Art. 21(2)(j) limits the value of any single compromised partner identity feeding configuration tables or commanding tools.

  • nis2Art. 21(3)
    addresses
    high
    direct

    Variations in process rigour, identity proofing, and toolchains across collaborator institutions are the canonical supplier-specific vulnerabilities Art. 21(3) requires the entity to consider when relying on cross-org pipelines.

  • nis2-implAnnex 11.2.1
    addresses
    moderate
    derived

    Access-rights to data portals, shared repositories and federated identity systems must be provisioned, modified and removed under documented procedures that match collaborator role tenure.

  • nis2-implAnnex 5.1.1
    addresses
    high
    derived

    Mission collaborators (universities, science operations centers, international partners) are direct suppliers under the supply-chain policy; the policy governs the security expectations and shared-credential discipline imposed on those collaborators.

  • nis2-implAnnex 5.1.6
    addresses
    high
    derived

    Mission collaborators (universities, science ops centers, international partners) require Annex 5.1.6 ongoing monitoring of cross-org credential hygiene and incident-disclosure compliance.

  • nis2-implAnnex 5.1.7
    addresses
    moderate
    derived

    This technique delivers attacker-modified calibration scripts, configuration tables, and payload tasks into mission workflows through collaborator ICT services, and Annex 5.1.7 obliges entities to review incidents related to those suppliers' ICT products and services and to analyse the risks presented by changes to them, taking timely mitigating measures. That duty to scrutinise supplier-originated changes and incidents is what makes the article relevant to compromised-partner artifacts traversing sanctioned paths.

  • nis2-implAnnex 8.1.1
    addresses
    moderate
    derived

    Cyber-hygiene awareness across collaborator organizations limits the social-engineering footprint of cross-org repositories and shared portals where collaborator accounts are most often the entry point.

ENISA controls

  • Third-party risk management explicitly covers science operations centers, instrument builders, and international partners in the SCRM scope.

  • ENISA-STL-2025-03-sD.21-i07
    relates to
    moderate

    Separation of development/testing/production environments is relevant to limiting a compromised collaborator lateral movement toward production, governing isolation rather than actively defending the collaborator-access vector.

  • Least-privilege access control on cross-organization tools and federated credentials limits the reach of a compromised collaborator into mission workflows.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, IA-0009.01 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.