Disruption
Description
Measures designed to temporarily impair the use or access to a system for a period of time. Threat actors may seek to disrupt communications from the victim spacecraft to the ground controllers or other interested parties. By disrupting communications during critical times, there is the potential impact of data being lost or critical actions not being performed. This could cause the spacecraft's purpose to be put into jeopardy depending on what communications were lost during the disruption. This behavior is different than Denial as this attack can also attempt to modify the data and messages as they are passed as a way to disrupt communications.
Mappings
EU regulation articles
IMP-0002 explicitly differs from denial in that it can also modify data and messages as they pass — within (2)(f)'s integrity-of-transmitted-data scope.
Disrupting spacecraft-to-ground communications during critical times is exactly the availability impact (2)(h) requires resilience and DoS-mitigation measures against, including the 'also after an incident' clause.
Disruption severe-incident notification (primary mapping: Art. 14(3)) follows the format and procedures specified by (14)(10)'s implementing acts.
Disruption that negatively affects the availability of important functions meets the 14(5)(a) severe-incident threshold and triggers manufacturer notification obligations under 14(3).
Disruption severe-incident notification (primary mapping: Art. 14(3)) cascades to (14)(4)'s notification timing schedule.
Disruption severe incidents (primary mapping: Art. 14(3)) may involve ongoing exploitation where premature notification could escalate impact; (14)(9)'s delay-grounds delegated acts are the governing instrument.
Disruption of communications at critical times is mitigated by 86(1)'s comprehensive backup-management policy enabling restoration of network and information systems with minimum downtime.
87(2)'s response-and-recovery plans must allow operators to quickly and effectively respond to disruptions and contain the adverse effects.
Disruption recovery (primary: Art. 87(2) BCDR) cascades to 87(4) — staff implementing disruption-response procedures need full and adequate training under 87(4).
Disruption significant-incident reporting (primary: Art. 93(6)) cascades to 93(3) — when the operator qualifies as essential/important under NIS2, reporting is routed via CSIRTs per 93(3).
Disruption significant-incident reporting (primary: Art. 93(6)) relates to 93(4)'s without-prejudice-to-NIS2-and-CER coordination clause — reporting under EU Space Act does not waive NIS2 Art. 23 obligations.
Disruption that causes severe operational disruption of space activities or considerable financial loss meets the 93(6) significant-incident threshold and triggers the 93(1)/(2) reporting obligations.
Disruption significant-incident reporting (primary: Art. 93(6)) cascades to 93(7)'s 12h/24h/72h timing schedule — early warning, intermediate update, and follow-up reports.
Disruption-incident notification (primary: Art. 93(6)) relates to 93(8) — Commission's implementing acts specify the format and templates of the report content under 93(7).
Temporary communications impairment during operationally critical windows is a paradigmatic incident the entity's incident-handling capability under Art. 21(2)(b) is designed to detect and respond to, including the data-modification variants distinct from outright denial.
Business-continuity planning, backup communications paths, and crisis-management procedures under Art. 21(2)(c) limit mission impact when adversaries disrupt or modify communications during critical times.
Disruption causing severe operational impairment of the entity's services meets the Art. 23(3)(a) significance threshold and triggers the Art. 23(1) reporting regime.
Primary mapping to Art. 23(1) treats disruption as a significant incident. Art. 23(2) timing applies once Art. 23(1) is triggered.
Primary mapping to Art. 23(1) treats disruption as significant. Art. 23(3) significance test is met directly by the operational-disruption criterion; cross-border impact applies when affected services span Member States.
Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Disruption is usually directly observable, so the 24-hour early warning starts at the disruption moment.
Disruption is operator-visible; Annex 3.3.1 mechanism enables rapid employee escalation that feeds 3.4 assessment ahead of automated detection.
Disruption events trigger the assessment gate before Annex 3.5.1 response — scope, expected duration and recoverability are classified per Annex 3.4.1.
Operational assessment criteria for disruption (downtime, affected services, cross-customer impact) feed directly into Annex 3.5.1 response activation.
Incident-response procedures (containment, eradication, recovery) are the procedural mechanism that converts the observation of disruption into the restoration of mission service.
Post-incident review of disruption events identifies the failure modes (link saturation, parser overload, partial responder availability) that allowed the event.
Improvements driven by disruption post-incident reviews typically include continuity-plan updates, redundancy adjustments and detection refinements.
Planned-interval Annex 3.6.3 review tracks whether disruption events are captured by post-incident-review discipline.
Disruption is precisely the temporary impairment business-continuity-and-disaster-recovery plans are established to manage; the implementing regulation requires the entity to lay down and maintain such plans for exactly this class of mission-affecting events.
Primary mapping to Annex 4.1.1 (BCDR plan) implies the test-cadence obligation: Annex 4.1.4 requires the plans to be tested, reviewed and updated at planned intervals so they are operationally viable for disruption events.
Crisis-management procedures handle escalations beyond routine incident response, which is appropriate for sustained or wide-area disruptions affecting mission communications.
ENISA controls
A documented incident response plan governs the procedures for responding to disruption events, relevant to shortening their duration rather than actively preventing the disruption.
Incident Recovery Plan with detailed recovery procedures and roles is the operator-side discipline through which temporary disruption is contained and reversed.
Critical Services Delivery Requirements establish resilience requirements for all operating states including under-attack and recovery — directly governing IMP-0002 disruption response.
System redundancy across ground-segment infrastructure preserves continuity when one path is disrupted, the canonical operator-side defense against IMP-0002.
Cross-reference controls
T1489 'Service Stop' is in MITRE impact tactic and addresses temporary impairment of system services; SPARTA IMP-0002 'Disruption' is the parent-level spacecraft equivalent (temporarily impair use/access without physical damage). Tactic and activity align directly.
T1499 'Endpoint Denial of Service' covers temporary endpoint unavailability via resource exhaustion; SPARTA IMP-0002 'Disruption' includes endpoint-DoS-style temporary impairment as one of its modes. Tactic-aligned but moderate because IMP-0002's scope is broader than endpoint DoS.
T0813 'Denial of Control' is in MITRE ICS impact tactic and addresses temporary loss of operator ability to interact with process controls; SPARTA IMP-0002 'Disruption' is the parent-level spacecraft equivalent (temporarily impair use/access without physical damage). Tactic and activity align directly.
The practice requires that intentional disruptions be carried into anomaly detection, response, and recovery plans across both segments. Disruption is the named case, and planned recovery is active recovery against it, which meets the mitigates bar.
CP-10 mitigates IMP-0002 by enabling reconstitution of disrupted mission operations.
CP-13 addresses alternative security mechanisms that limit disruption-driven coercion.
CP-2 (Contingency Plan) addresses mission-continuity planning whose enforcement limits IMP-0002 disruption impact.
CP-7 (Alternate Processing Site) addresses ground-side resilience to disruption.
IR-4 mitigates IMP-0002 by detecting and responding to disruption indicators.
T2024 'Transmitted Data Manipulation' covers the disruption variant where an attacker modifies/distorts data and messages as they pass — directly aligned with IMP-0002's distinction from pure denial (also attempts to modify and disrupt communications).
T2026 'Temporary loss to telecommand satellite' is the direct cross-framework counterpart of IMP-0002 Disruption — both describe attacker actions that temporarily impair the use or access to the spacecraft's command and communication capabilities.
Cite as SafeMode Space, IMP-0002 (SPARTA v3.2).