All techniques
IMP-0001
ST0009Impact

Deception (or Misdirection)

Description

Measures designed to mislead an adversary by manipulation, distortion, or falsification of evidence or information into a system to induce the adversary to react in a manner prejudicial to their interests. Threat actors may seek to deceive mission stakeholders (or even military decision makers) for a multitude of reasons. Telemetry values could be modified, attacks could be designed to intentionally mimic another threat actor's TTPs, and even allied ground infrastructure could be compromised and used as the source of communications to the spacecraft.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    moderate
    direct

    Compromised allied ground infrastructure used as the source of communications to the spacecraft is an authentication-bypass scenario (2)(d) requires the spacecraft's access-management to resist regardless of source apparent legitimacy.

  • craAnnex I, Part I, (2)(f)
    addresses
    high
    direct

    Modifying telemetry values to induce mission stakeholders to react in error is the canonical case (2)(f) integrity addresses — manipulation of transmitted data not authorized by the user, with the corruption-reporting requirement.

  • craArt. 14(10)
    relates to
    moderate
    direct

    Deception-impact severe-incident notification (primary mapping: Art. 14(3)) follows the format and procedures specified by (14)(10)'s implementing acts.

  • craArt. 14(3)
    triggers obligation
    moderate
    direct

    Deception that affects the authenticity or integrity of important data or functions meets the Art. 14(5)(a) severe-incident threshold and triggers the 14(3) notification obligation to the CSIRT-coordinator and ENISA.

  • craArt. 14(4)
    addresses
    moderate
    direct

    Deception-impact severe-incident notification (primary mapping: Art. 14(3)) cascades to (14)(4)'s 24h/72h/1mo timing schedule for severe incidents.

  • craArt. 14(9)
    relates to
    moderate
    direct

    Deception-impact severe incidents (primary mapping: Art. 14(3)) include scenarios where investigation continuity may justify delayed dissemination; (14)(9) provides the legal-grounds framework.

  • eu-space-actArt. 84(2)
    addresses
    high
    direct

    Modifying telemetry values to mislead mission stakeholders is the canonical case 84(2)'s integrity property addresses — Annex VII point 5.1 includes integrity protection on transmitted data.

  • eu-space-actArt. 85(1)
    addresses
    moderate
    direct

    Compromised allied ground infrastructure presenting itself as the source of communications is an authentication-bypass scenario; 85(1)'s cryptographic concept must defeat it through end-to-end auth.

  • eu-space-actArt. 91(1)
    addresses
    moderate
    direct

    Deception incidents trigger the 91(1) incident-management process — detection, identification, handling, and response to misdirection events.

  • nis2Art. 21(2)(b)
    addresses
    high
    derived

    Falsified telemetry, mimicked TTPs, and compromised allied infrastructure used to mislead operators are textbook scenarios the entity's incident-handling capability under Art. 21(2)(b) must detect via cross-validation of evidence, indicators of compromise, and chain-of-custody discipline.

  • nis2Art. 21(2)(h)
    addresses
    moderate
    inferred

    Authenticated telemetry and uplink make telemetry mimicry and falsified-source communications visible at receipt, but they do not cover the dominant scope of broad deception through falsification and TTP mimicry, where the operative control is integrity-monitoring and access control. Under the strict bar the cryptographic control covers the message-authenticity vector but not the defining deception scope, so at NIS2 Art. 21(2)(h) the relationship is addresses.

  • nis2Art. 23(1)
    triggers obligation
    moderate
    derived

    Confirmed deception of mission decision-making is a significant compromise of the entity's operational integrity and is reportable under Art. 23(1) once detected.

  • nis2Art. 23(2)
    addresses
    moderate
    derived

    Primary mapping to Art. 23(1) treats deception/misdirection at impact scale as a significant incident. Art. 23(2) timing applies once Art. 23(1) is triggered.

  • nis2Art. 23(3)
    relates to
    moderate
    derived

    Primary mapping to Art. 23(1) treats deception as significant. Art. 23(3) significance test is met by the considerable-damage criterion (induced wrong reactions by mission stakeholders) and the affecting-other-persons criterion (downstream consumers of falsified telemetry).

  • nis2Art. 23(4)
    addresses
    moderate
    derived

    Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Deception is often detected only after downstream wrong decisions surface, so awareness lags the deception window.

  • nis2-implAnnex 11.6.1
    addresses
    moderate
    derived

    Telemetry-deception relies on falsifying inputs that subsystems treat as authoritative; secure-authentication procedures bind data to verifiable identities and resist forged or modified telemetry being accepted as true.

  • nis2-implAnnex 3.2.1
    addresses
    high
    derived

    Monitoring-and-logging procedures must surface telemetry inconsistencies, cross-source disagreements and anomalous source patterns that signal deception or misdirection.

  • nis2-implAnnex 3.3.1
    addresses
    moderate
    derived

    Operators are often the first to notice deception (telemetry that does not match expected behaviour); Annex 3.3.1 ensures they have a mechanism to escalate without friction, feeding 3.4 assessment.

  • nis2-implAnnex 3.4.1
    addresses
    moderate
    derived

    Deception requires careful assessment to distinguish manipulated telemetry from genuine anomalies; Annex 3.4.1 is the assessment gate that must classify events before Annex 3.5.1 response activates.

  • nis2-implAnnex 3.4.2
    addresses
    high
    derived

    Operational assessment for deception relies on cross-source telemetry consistency checks and severity assignment based on downstream wrong-decision exposure.

  • nis2-implAnnex 3.5.1
    addresses
    moderate
    derived

    Incident-response procedures govern containment and recovery once deception is identified; documented procedures bound the time the entity operates on falsified evidence.

  • nis2-implAnnex 3.6.1
    addresses
    moderate
    derived

    Post-incident review is essential for deception events because the entity must reconstruct which downstream decisions were made on falsified evidence and remediate accordingly.

  • nis2-implAnnex 3.6.2
    addresses
    moderate
    derived

    Post-incident review must improve the security approach: deception events typically expose telemetry-validation gaps the entity must close.

  • nis2-implAnnex 3.6.3
    addresses
    moderate
    derived

    Planned-interval review tracks whether deception events are captured by the post-incident-review process.

ENISA controls

  • Integrity checking surfaces telemetry-value modifications and falsified evidence that IMP-0001 introduces.

  • Mission cyber-actor-actions detection function is positioned to surface the deception/misdirection that defines IMP-0001.

  • Incident response procedures including SIEM-driven correlation across signals reduce the time deception goes undetected and the effect of false TTPs.

Cross-reference controls

  • mitre-attack-enterpriseT1565Data Manipulation
    addresses
    high

    T1565 'Data Manipulation' is in MITRE impact tactic and addresses adversary insertion/deletion/manipulation of data to influence external outcomes — exact concept-match for SPARTA IMP-0001 'Deception (or Misdirection)' where modified telemetry/data misleads stakeholders. Tactic and activity align directly.

  • mitre-attack-icsT0832Manipulation of View
    addresses
    high

    T0832 'Manipulation of View' is in MITRE ICS impact tactic and addresses adversary manipulation of information reported back to operators or controllers — exact concept-match for SPARTA IMP-0001 'Deception (or Misdirection)' where modified telemetry/data misleads stakeholders. Tactic and activity align directly.

  • nasa-bpgMI-MA-01Mission Recovery Function
    addresses
    moderate

    Deception is an integrity effect rather than a disruption, so the practice's anomaly-detection arm governs it while its recovery arm, written for disruptions, does not reach it.

  • nist-80053-rev5AU-12Audit Record Generation
    addresses
    moderate

    AU-12 addresses audit-record generation whose review reveals deception-driven inconsistency.

  • nist-80053-rev5IR-4Incident Handling
    addresses
    moderate

    IR-4 mitigates IMP-0001 by detecting and responding to deception indicators.

  • nist-80053-rev5SC-23Session Authenticity
    addresses
    moderate

    IMP-0001 is broad deception via falsification of telemetry, mimicry of another actor's TTPs, and compromised-but-legitimate ground infrastructure used as the communications source. SC-23 session authenticity defeats only the fabricated-origin slice; a compromised-legitimate source passes session authenticity, so the dominant deception scope is uncovered and the relationship is addresses.

  • nist-80053-rev5SI-4System Monitoring
    addresses
    moderate

    SI-4 mitigates IMP-0001 by surfacing inconsistencies between observed mission state and expected behaviour.

  • space-shieldT2024Transmitted Data Manipulation
    addresses
    moderate

    T2024 'Transmitted Data Manipulation' covers modifying transmitted data to lead the system owner to erroneous decisions — addresses IMP-0001's modification of telemetry values to mislead mission stakeholders.

  • space-shieldT2040Masquerading
    addresses
    moderate

    T2040 'Masquerading' covers manipulating artifact features to appear legitimate — addresses IMP-0001's design of attacks that intentionally mimic another threat actor's TTPs and use of allied ground infrastructure as the masqueraded source.

Cite as SafeMode Space, IMP-0001 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.