Deception (or Misdirection)
Description
Measures designed to mislead an adversary by manipulation, distortion, or falsification of evidence or information into a system to induce the adversary to react in a manner prejudicial to their interests. Threat actors may seek to deceive mission stakeholders (or even military decision makers) for a multitude of reasons. Telemetry values could be modified, attacks could be designed to intentionally mimic another threat actor's TTPs, and even allied ground infrastructure could be compromised and used as the source of communications to the spacecraft.
Mappings
EU regulation articles
Compromised allied ground infrastructure used as the source of communications to the spacecraft is an authentication-bypass scenario (2)(d) requires the spacecraft's access-management to resist regardless of source apparent legitimacy.
Modifying telemetry values to induce mission stakeholders to react in error is the canonical case (2)(f) integrity addresses — manipulation of transmitted data not authorized by the user, with the corruption-reporting requirement.
Deception-impact severe-incident notification (primary mapping: Art. 14(3)) follows the format and procedures specified by (14)(10)'s implementing acts.
Deception that affects the authenticity or integrity of important data or functions meets the Art. 14(5)(a) severe-incident threshold and triggers the 14(3) notification obligation to the CSIRT-coordinator and ENISA.
Deception-impact severe-incident notification (primary mapping: Art. 14(3)) cascades to (14)(4)'s 24h/72h/1mo timing schedule for severe incidents.
Deception-impact severe incidents (primary mapping: Art. 14(3)) include scenarios where investigation continuity may justify delayed dissemination; (14)(9) provides the legal-grounds framework.
Modifying telemetry values to mislead mission stakeholders is the canonical case 84(2)'s integrity property addresses — Annex VII point 5.1 includes integrity protection on transmitted data.
Compromised allied ground infrastructure presenting itself as the source of communications is an authentication-bypass scenario; 85(1)'s cryptographic concept must defeat it through end-to-end auth.
Deception incidents trigger the 91(1) incident-management process — detection, identification, handling, and response to misdirection events.
Falsified telemetry, mimicked TTPs, and compromised allied infrastructure used to mislead operators are textbook scenarios the entity's incident-handling capability under Art. 21(2)(b) must detect via cross-validation of evidence, indicators of compromise, and chain-of-custody discipline.
Authenticated telemetry and uplink make telemetry mimicry and falsified-source communications visible at receipt, but they do not cover the dominant scope of broad deception through falsification and TTP mimicry, where the operative control is integrity-monitoring and access control. Under the strict bar the cryptographic control covers the message-authenticity vector but not the defining deception scope, so at NIS2 Art. 21(2)(h) the relationship is addresses.
Confirmed deception of mission decision-making is a significant compromise of the entity's operational integrity and is reportable under Art. 23(1) once detected.
Primary mapping to Art. 23(1) treats deception/misdirection at impact scale as a significant incident. Art. 23(2) timing applies once Art. 23(1) is triggered.
Primary mapping to Art. 23(1) treats deception as significant. Art. 23(3) significance test is met by the considerable-damage criterion (induced wrong reactions by mission stakeholders) and the affecting-other-persons criterion (downstream consumers of falsified telemetry).
Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Deception is often detected only after downstream wrong decisions surface, so awareness lags the deception window.
Telemetry-deception relies on falsifying inputs that subsystems treat as authoritative; secure-authentication procedures bind data to verifiable identities and resist forged or modified telemetry being accepted as true.
Monitoring-and-logging procedures must surface telemetry inconsistencies, cross-source disagreements and anomalous source patterns that signal deception or misdirection.
Operators are often the first to notice deception (telemetry that does not match expected behaviour); Annex 3.3.1 ensures they have a mechanism to escalate without friction, feeding 3.4 assessment.
Deception requires careful assessment to distinguish manipulated telemetry from genuine anomalies; Annex 3.4.1 is the assessment gate that must classify events before Annex 3.5.1 response activates.
Operational assessment for deception relies on cross-source telemetry consistency checks and severity assignment based on downstream wrong-decision exposure.
Incident-response procedures govern containment and recovery once deception is identified; documented procedures bound the time the entity operates on falsified evidence.
Post-incident review is essential for deception events because the entity must reconstruct which downstream decisions were made on falsified evidence and remediate accordingly.
Post-incident review must improve the security approach: deception events typically expose telemetry-validation gaps the entity must close.
Planned-interval review tracks whether deception events are captured by the post-incident-review process.
ENISA controls
Integrity checking surfaces telemetry-value modifications and falsified evidence that IMP-0001 introduces.
Mission cyber-actor-actions detection function is positioned to surface the deception/misdirection that defines IMP-0001.
Incident response procedures including SIEM-driven correlation across signals reduce the time deception goes undetected and the effect of false TTPs.
Cross-reference controls
T1565 'Data Manipulation' is in MITRE impact tactic and addresses adversary insertion/deletion/manipulation of data to influence external outcomes — exact concept-match for SPARTA IMP-0001 'Deception (or Misdirection)' where modified telemetry/data misleads stakeholders. Tactic and activity align directly.
T0832 'Manipulation of View' is in MITRE ICS impact tactic and addresses adversary manipulation of information reported back to operators or controllers — exact concept-match for SPARTA IMP-0001 'Deception (or Misdirection)' where modified telemetry/data misleads stakeholders. Tactic and activity align directly.
Deception is an integrity effect rather than a disruption, so the practice's anomaly-detection arm governs it while its recovery arm, written for disruptions, does not reach it.
AU-12 addresses audit-record generation whose review reveals deception-driven inconsistency.
IR-4 mitigates IMP-0001 by detecting and responding to deception indicators.
IMP-0001 is broad deception via falsification of telemetry, mimicry of another actor's TTPs, and compromised-but-legitimate ground infrastructure used as the communications source. SC-23 session authenticity defeats only the fabricated-origin slice; a compromised-legitimate source passes session authenticity, so the dominant deception scope is uncovered and the relationship is addresses.
SI-4 mitigates IMP-0001 by surfacing inconsistencies between observed mission state and expected behaviour.
T2024 'Transmitted Data Manipulation' covers modifying transmitted data to lead the system owner to erroneous decisions — addresses IMP-0001's modification of telemetry values to mislead mission stakeholders.
T2040 'Masquerading' covers manipulating artifact features to appear legitimate — addresses IMP-0001's design of attacks that intentionally mimic another threat actor's TTPs and use of allied ground infrastructure as the masqueraded source.
Cite as SafeMode Space, IMP-0001 (SPARTA v3.2).