All techniques
IA-0013
ST0003Initial Access

Compromise Host Spacecraft

Description

The inverse of "IA-0006: Compromise Hosted Payload", this technique describes adversaries that are targeting a hosted payload, the host space vehicle (SV) can serve as an initial access vector to compromise the payload through vulnerabilities in the SV's onboard systems, communication interfaces, or software. If the SV's command and control systems are exploited, an attacker could gain unauthorized access to the vehicle's internal network. Once inside, the attacker may laterally move to the hosted payload, particularly if it shares data buses, processors, or communication links with the vehicle.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(j)
    addresses
    high
    derived

    Limited attack surfaces apply to host-bus/payload interfaces from the host-bus side: manufacturer must design the host bus to expose minimal trust to the hosted payload.

  • craAnnex I, Part I, (2)(k)
    addresses
    moderate
    derived

    Exploitation mitigation mechanisms (separation kernels, partition isolation) bound the host's reach into the payload, the inverse of IA-0006 with the same isolation discipline.

  • craAnnex I, Part II, (3)
    addresses
    moderate
    direct

    IA-0013 gains initial access by exploiting vulnerabilities in the host spacecraft's onboard systems, communication interfaces, and software, which are exactly the weaknesses that the obligation to apply effective and regular tests and reviews of the product's security is meant to surface. Regular security testing of the host vehicle reduces the unaddressed onboard flaws an adversary uses to reach the hosted payload, supporting an addresses-level relationship.

  • eu-space-actArt. 84(3)
    mitigates
    moderate
    direct

    84(3)'s only-authorized-devices rule applies to host-payload bridges — limiting which host subsystems can issue commands or write to the hosted payload.

  • eu-space-actArt. 91(3)
    addresses
    high
    direct

    When the host SV is the initial-access vector to a hosted payload, 91(3)'s requirement to inform the third-party entity (and the pre-defined-agreements clause) is the operator's procedural obligation; the agreement scope shapes how access between host and payload is constrained.

  • nis2Art. 21(2)(d)
    addresses
    moderate
    direct

    When the host SV operator is the payload's service provider (rideshare, hosted-payload), Art. 21(2)(d)'s supplier-relationship security obligation governs the trust framework over the bus the payload depends on.

  • nis2Art. 21(2)(i)
    addresses
    high
    direct

    Bus/payload data routes, shared processors, and communication links are the asset class Art. 21(2)(i)'s access-control + asset-management obligation governs — preventing the bus's compromise from cascading into the hosted payload through shared internal interfaces.

  • nis2Art. 21(3)
    addresses
    moderate
    direct

    Host SV's segmentation and onboard-network discipline vary by operator; Art. 21(3) requires the payload's parent entity to consider those host-specific vulnerabilities when riding the bus.

  • nis2-implAnnex 5.1.1
    addresses
    high
    derived

    Where the entity's payload is hosted on a third-party spacecraft, the host operator is a direct supplier under the supply-chain policy; the policy governs the integration-security expectations imposed on the host bus.

  • nis2-implAnnex 5.1.6
    addresses
    moderate
    derived

    Host-spacecraft operators are persistent-supplier counterparties; Annex 5.1.6 monitoring detects host-side posture changes that would expose the entity's hosted payload to host-bus compromise.

  • nis2-implAnnex 5.1.7
    addresses
    moderate
    derived

    Annex 5.1.7 follow-up procedures operationalize host-operator monitoring signals into segmentation, telemetry-isolation and contractual responses.

  • nis2-implAnnex 6.8.1
    addresses
    high
    derived

    Segmentation between hosted payload and host-bus subsystems is the architectural control that bounds the host's reach into the payload — the inverse direction of IA-0006 but the same segmentation discipline.

ENISA controls

  • Third-party risk management between host operator and payload operator is the agreement-side discipline that constrains the IA-0013 vector.

  • Supplier security management on host-spacecraft providers establishes the audit baseline limiting host-side compromise propagation into hosted payloads.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, IA-0013 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.