All techniques
IMP-0002
ST0009Impact

Disruption

Description

Measures designed to temporarily impair the use or access to a system for a period of time. Threat actors may seek to disrupt communications from the victim spacecraft to the ground controllers or other interested parties. By disrupting communications during critical times, there is the potential impact of data being lost or critical actions not being performed. This could cause the spacecraft's purpose to be put into jeopardy depending on what communications were lost during the disruption. This behavior is different than Denial as this attack can also attempt to modify the data and messages as they are passed as a way to disrupt communications.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(f)
    addresses
    moderate
    direct

    IMP-0002 explicitly differs from denial in that it can also modify data and messages as they pass — within (2)(f)'s integrity-of-transmitted-data scope.

  • craAnnex I, Part I, (2)(h)
    addresses
    high
    direct

    Disrupting spacecraft-to-ground communications during critical times is exactly the availability impact (2)(h) requires resilience and DoS-mitigation measures against, including the 'also after an incident' clause.

  • craArt. 14(10)
    relates to
    moderate
    direct

    Disruption severe-incident notification (primary mapping: Art. 14(3)) follows the format and procedures specified by (14)(10)'s implementing acts.

  • craArt. 14(3)
    triggers obligation
    moderate
    direct

    Disruption that negatively affects the availability of important functions meets the 14(5)(a) severe-incident threshold and triggers manufacturer notification obligations under 14(3).

  • craArt. 14(4)
    addresses
    high
    direct

    Disruption severe-incident notification (primary mapping: Art. 14(3)) cascades to (14)(4)'s notification timing schedule.

  • craArt. 14(9)
    relates to
    moderate
    direct

    Disruption severe incidents (primary mapping: Art. 14(3)) may involve ongoing exploitation where premature notification could escalate impact; (14)(9)'s delay-grounds delegated acts are the governing instrument.

  • eu-space-actArt. 86(1)
    addresses
    moderate
    direct

    Disruption of communications at critical times is mitigated by 86(1)'s comprehensive backup-management policy enabling restoration of network and information systems with minimum downtime.

  • eu-space-actArt. 87(2)
    addresses
    high
    direct

    87(2)'s response-and-recovery plans must allow operators to quickly and effectively respond to disruptions and contain the adverse effects.

  • eu-space-actArt. 87(4)
    addresses
    moderate
    direct

    Disruption recovery (primary: Art. 87(2) BCDR) cascades to 87(4) — staff implementing disruption-response procedures need full and adequate training under 87(4).

  • eu-space-actArt. 93(3)
    addresses
    moderate
    direct

    Disruption significant-incident reporting (primary: Art. 93(6)) cascades to 93(3) — when the operator qualifies as essential/important under NIS2, reporting is routed via CSIRTs per 93(3).

  • eu-space-actArt. 93(4)
    relates to
    moderate
    direct

    Disruption significant-incident reporting (primary: Art. 93(6)) relates to 93(4)'s without-prejudice-to-NIS2-and-CER coordination clause — reporting under EU Space Act does not waive NIS2 Art. 23 obligations.

  • eu-space-actArt. 93(6)
    triggers obligation
    moderate
    direct

    Disruption that causes severe operational disruption of space activities or considerable financial loss meets the 93(6) significant-incident threshold and triggers the 93(1)/(2) reporting obligations.

  • eu-space-actArt. 93(7)
    addresses
    high
    direct

    Disruption significant-incident reporting (primary: Art. 93(6)) cascades to 93(7)'s 12h/24h/72h timing schedule — early warning, intermediate update, and follow-up reports.

  • eu-space-actArt. 93(8)
    relates to
    moderate
    direct

    Disruption-incident notification (primary: Art. 93(6)) relates to 93(8) — Commission's implementing acts specify the format and templates of the report content under 93(7).

  • nis2Art. 21(2)(b)
    addresses
    high
    derived

    Temporary communications impairment during operationally critical windows is a paradigmatic incident the entity's incident-handling capability under Art. 21(2)(b) is designed to detect and respond to, including the data-modification variants distinct from outright denial.

  • nis2Art. 21(2)(c)
    addresses
    moderate
    direct

    Business-continuity planning, backup communications paths, and crisis-management procedures under Art. 21(2)(c) limit mission impact when adversaries disrupt or modify communications during critical times.

  • nis2Art. 23(1)
    triggers obligation
    high
    direct

    Disruption causing severe operational impairment of the entity's services meets the Art. 23(3)(a) significance threshold and triggers the Art. 23(1) reporting regime.

  • nis2Art. 23(2)
    addresses
    moderate
    derived

    Primary mapping to Art. 23(1) treats disruption as a significant incident. Art. 23(2) timing applies once Art. 23(1) is triggered.

  • nis2Art. 23(3)
    relates to
    high
    derived

    Primary mapping to Art. 23(1) treats disruption as significant. Art. 23(3) significance test is met directly by the operational-disruption criterion; cross-border impact applies when affected services span Member States.

  • nis2Art. 23(4)
    addresses
    moderate
    derived

    Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Disruption is usually directly observable, so the 24-hour early warning starts at the disruption moment.

  • nis2-implAnnex 3.3.1
    addresses
    moderate
    derived

    Disruption is operator-visible; Annex 3.3.1 mechanism enables rapid employee escalation that feeds 3.4 assessment ahead of automated detection.

  • nis2-implAnnex 3.4.1
    addresses
    moderate
    derived

    Disruption events trigger the assessment gate before Annex 3.5.1 response — scope, expected duration and recoverability are classified per Annex 3.4.1.

  • nis2-implAnnex 3.4.2
    addresses
    moderate
    derived

    Operational assessment criteria for disruption (downtime, affected services, cross-customer impact) feed directly into Annex 3.5.1 response activation.

  • nis2-implAnnex 3.5.1
    addresses
    moderate
    derived

    Incident-response procedures (containment, eradication, recovery) are the procedural mechanism that converts the observation of disruption into the restoration of mission service.

  • nis2-implAnnex 3.6.1
    addresses
    moderate
    derived

    Post-incident review of disruption events identifies the failure modes (link saturation, parser overload, partial responder availability) that allowed the event.

  • nis2-implAnnex 3.6.2
    addresses
    moderate
    derived

    Improvements driven by disruption post-incident reviews typically include continuity-plan updates, redundancy adjustments and detection refinements.

  • nis2-implAnnex 3.6.3
    addresses
    moderate
    derived

    Planned-interval Annex 3.6.3 review tracks whether disruption events are captured by post-incident-review discipline.

  • nis2-implAnnex 4.1.1
    addresses
    high
    derived

    Disruption is precisely the temporary impairment business-continuity-and-disaster-recovery plans are established to manage; the implementing regulation requires the entity to lay down and maintain such plans for exactly this class of mission-affecting events.

  • nis2-implAnnex 4.1.4
    addresses
    moderate
    derived

    Primary mapping to Annex 4.1.1 (BCDR plan) implies the test-cadence obligation: Annex 4.1.4 requires the plans to be tested, reviewed and updated at planned intervals so they are operationally viable for disruption events.

  • nis2-implAnnex 4.3.1
    addresses
    moderate
    derived

    Crisis-management procedures handle escalations beyond routine incident response, which is appropriate for sustained or wide-area disruptions affecting mission communications.

ENISA controls

  • A documented incident response plan governs the procedures for responding to disruption events, relevant to shortening their duration rather than actively preventing the disruption.

  • Incident Recovery Plan with detailed recovery procedures and roles is the operator-side discipline through which temporary disruption is contained and reversed.

  • Critical Services Delivery Requirements establish resilience requirements for all operating states including under-attack and recovery — directly governing IMP-0002 disruption response.

  • System redundancy across ground-segment infrastructure preserves continuity when one path is disrupted, the canonical operator-side defense against IMP-0002.

Cross-reference controls

  • mitre-attack-enterpriseT1489Service Stop
    addresses
    high

    T1489 'Service Stop' is in MITRE impact tactic and addresses temporary impairment of system services; SPARTA IMP-0002 'Disruption' is the parent-level spacecraft equivalent (temporarily impair use/access without physical damage). Tactic and activity align directly.

  • mitre-attack-enterpriseT1499Endpoint Denial of Service
    addresses
    moderate

    T1499 'Endpoint Denial of Service' covers temporary endpoint unavailability via resource exhaustion; SPARTA IMP-0002 'Disruption' includes endpoint-DoS-style temporary impairment as one of its modes. Tactic-aligned but moderate because IMP-0002's scope is broader than endpoint DoS.

  • mitre-attack-icsT0813Denial of Control
    addresses
    high

    T0813 'Denial of Control' is in MITRE ICS impact tactic and addresses temporary loss of operator ability to interact with process controls; SPARTA IMP-0002 'Disruption' is the parent-level spacecraft equivalent (temporarily impair use/access without physical damage). Tactic and activity align directly.

  • nasa-bpgMI-MA-01Mission Recovery Function
    mitigates
    moderate

    The practice requires that intentional disruptions be carried into anomaly detection, response, and recovery plans across both segments. Disruption is the named case, and planned recovery is active recovery against it, which meets the mitigates bar.

  • nist-80053-rev5CP-10System Recovery and Reconstitution
    addresses
    moderate

    CP-10 mitigates IMP-0002 by enabling reconstitution of disrupted mission operations.

  • nist-80053-rev5CP-13Alternative Security Mechanisms
    addresses
    moderate

    CP-13 addresses alternative security mechanisms that limit disruption-driven coercion.

  • nist-80053-rev5CP-2Contingency Plan
    addresses
    moderate

    CP-2 (Contingency Plan) addresses mission-continuity planning whose enforcement limits IMP-0002 disruption impact.

  • nist-80053-rev5CP-7Alternate Processing Site
    addresses
    moderate

    CP-7 (Alternate Processing Site) addresses ground-side resilience to disruption.

  • nist-80053-rev5IR-4Incident Handling
    addresses
    moderate

    IR-4 mitigates IMP-0002 by detecting and responding to disruption indicators.

  • space-shieldT2024Transmitted Data Manipulation
    addresses
    moderate

    T2024 'Transmitted Data Manipulation' covers the disruption variant where an attacker modifies/distorts data and messages as they pass — directly aligned with IMP-0002's distinction from pure denial (also attempts to modify and disrupt communications).

  • T2026 'Temporary loss to telecommand satellite' is the direct cross-framework counterpart of IMP-0002 Disruption — both describe attacker actions that temporarily impair the use or access to the spacecraft's command and communication capabilities.

Cite as SafeMode Space, IMP-0002 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.