All techniques
IA-0009.03
ST0003Initial Access
sub-technique

User Segment

Parent: IA-0009

Description

The “user segment” encompasses end users and their equipment that interact with mission services, SATCOM terminals, customer ground gateways, tasking portals, and downstream processing pipelines for delivered data. Where these environments interconnect with mission cores, a compromised user domain becomes a springboard. Attackers can inject malformed tasking requests that propagate into payload scheduling, craft user-plane messages that traverse gateways into control or management planes, or seed data products that flow back to mission processing systems and automation. In broadband constellations and hosted services, user terminals may share infrastructure with TT&C or provider management networks, creating opportunities to pivot from customer equipment into provider-run nodes that the spacecraft trusts.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    moderate
    derived

    Authentication on user-segment interfaces bounds what user-segment compromise can reach in the product's commanding or telemetry-distribution backends.

  • craAnnex I, Part I, (2)(j)
    addresses
    moderate
    derived

    Limited attack surfaces apply to user-segment-facing interfaces (terminal APIs, customer gateways); products should expose minimal trust through these edges to prevent user-segment compromise propagating into mission systems.

  • eu-space-actArt. 84(3)
    addresses
    moderate
    direct

    When user-plane messages traverse gateways into control or management planes, 84(3)'s only-authorized-devices rule governs which user terminals can reach control systems.

  • eu-space-actArt. 92(1)
    addresses
    moderate
    direct

    User-segment compromise targets terminals, gateways, and tasking portals; 92(1)'s information-security contractual obligation covers commercial user-side service relationships.

  • nis2Art. 21(2)(d)
    addresses
    moderate
    direct

    Where user-segment infrastructure (SATCOM terminals, customer gateways, tasking portals) shares networks with TT&C or provider management, those interconnections are supplier-relationship touchpoints Art. 21(2)(d)'s obligation governs.

  • nis2Art. 21(2)(i)
    addresses
    moderate
    direct

    User-plane and control/management-plane separation is access-control discipline; Art. 21(2)(i)'s access-control + asset-management obligation governs the gateways through which user-segment traffic must not reach mission cores.

  • nis2Art. 21(3)
    addresses
    high
    derived

    Primary mapping to Art. 21(2)(d) covers the user-segment supplier relationship. Art. 21(3) extends to assessment of those user-segment suppliers' secure-development practices and disclosure obligations, since user-segment compromises propagate from supplier-side weaknesses into the operator's environment.

  • nis2-implAnnex 11.2.1
    addresses
    moderate
    derived

    Access-rights to tasking portals, customer gateways and downstream processing pipelines must be provisioned and revoked under documented procedures; over-broad user-segment access is the enabler of this technique.

  • nis2-implAnnex 5.1.1
    addresses
    high
    derived

    User-segment equipment suppliers, downstream processing partners and customer-gateway providers are direct suppliers under the supply-chain policy; the policy frames the security expectations imposed on the user-facing edge of the mission's distribution network.

  • nis2-implAnnex 5.1.6
    addresses
    moderate
    derived

    User-segment suppliers (terminal vendors, customer-gateway providers, downstream processors) require Annex 5.1.6 ongoing monitoring as user-segment compromise rides through their security posture.

  • nis2-implAnnex 5.1.7
    addresses
    moderate
    derived

    Annex 5.1.7 follow-up procedures convert user-segment monitoring signals into segmentation, access-restriction and supplier-replacement actions.

  • nis2-implAnnex 6.8.1
    addresses
    moderate
    derived

    Segmentation between user-segment networks and core mission systems is the architectural defense that prevents user-segment compromise from reaching commanding or telemetry-distribution backends.

ENISA controls

  • Access-based network segmentation between user-plane and management/control planes limits the propagation of malformed user-plane messages.

  • Intrusion detection at the user-segment-to-mission boundary identifies malformed tasking requests propagating into payload scheduling.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, IA-0009.03 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.