Degradation
Description
Measures designed to permanently impair (either partially or totally) the use of a system. Threat actors may target various subsystems or the hosted payload in such a way to rapidly increase it's degradation. This could potentially shorten the lifespan of the victim spacecraft.
Mappings
EU regulation articles
Permanent impairment of subsystems or hosted payload directly attacks the availability of essential functions; (2)(h)'s resilience obligation includes mitigation against persistent degradation, not only transient DoS.
Rapidly-induced subsystem degradation is a high-impact incident outcome (2)(k)'s exploitation-mitigation mechanisms (rate limiting on actuators, watchdog-bounded operation, sanity-checked thermal/power profiles) are meant to reduce.
Degradation-impact (primary mapping: Annex I, Part I, (2)(k)) cascades to (3) — exploitation-mitigation mechanisms (rate limiting, watchdog-bounded operation) require regular tests to validate effectiveness against degradation scenarios.
Degradation severe-incident notification (primary mapping: Art. 14(3)) follows the format and procedures specified by (14)(10)'s implementing acts.
Permanent degradation of an essential function meets the 14(5)(a) severe-incident threshold for availability impact and triggers 14(3) notification obligations.
Degradation severe-incident notification (primary mapping: Art. 14(3)) cascades to (14)(4)'s timing schedule for the persistent-availability-impact case.
Degradation severe incidents (primary mapping: Art. 14(3)) may warrant delayed dissemination during ongoing forensic analysis of root cause; (14)(9) is the applicable delegated-acts framework.
Permanent degradation of subsystems requires constellation-level redundancy under 86(3) — the only operator-side mitigation against persistent impairment.
87(2)'s response-and-recovery plans must allow operators to respond to and contain the adverse effects of degradation incidents.
Degradation recovery (primary: Art. 87(2) BCDR) cascades to 87(4) — recovery staff must be trained to identify persistent-degradation scenarios and apply graceful-fallback procedures.
Degradation significant-incident reporting (primary: Art. 93(6)) cascades to 93(3) — NIS2-routed reporting structure applies for essential-entity space operators experiencing persistent degradation.
Degradation reporting (primary: Art. 93(6)) relates to 93(4) — NIS2/CER coordination clause governs cross-regulatory reporting.
Permanent degradation causes severe operational disruption — meeting the 93(6) significant-incident threshold and triggering 93(1)/(2) reporting.
Degradation reporting (primary: Art. 93(6)) cascades to 93(7) — 12h/24h/72h schedule applies even when degradation is gradual.
Degradation reporting (primary: Art. 93(6)) relates to 93(8) — implementing-acts on report content/templates apply.
Permanent impairment of subsystems or the hosted payload is a significant compromise the entity's incident-handling capability under Art. 21(2)(b) must triage and document, including assessment of mission-lifespan impact.
Disaster-recovery planning and crisis-management procedures under Art. 21(2)(c) define how the entity continues to deliver mission services as accelerated subsystem degradation shortens the spacecraft's useful lifespan.
Permanent partial/total subsystem impairment is severe operational disruption with potentially considerable financial loss; Art. 23(1) reporting applies under both Art. 23(3) significance criteria.
Primary mapping to Art. 23(1) treats degradation as a significant incident. Art. 23(2) timing applies once Art. 23(1) is triggered.
Primary mapping to Art. 23(1) treats degradation as significant. Art. 23(3) significance test is met by the considerable-damage criterion (lifespan reduction, subsystem impairment) and frequently the financial-loss criterion via lost mission years.
Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Degradation has slow-onset signatures; the 24-hour clock starts at confirmation that degradation is adversarial rather than nominal.
Business-continuity-and-disaster-recovery plans address sustained mission-life impacts; degradation events that shorten useful life trigger the same continuity-planning obligations.
Primary mapping to Annex 4.1.1 (continuity planning for sustained mission-life impacts from degradation) implies Annex 4.1.4 test cadence: degradation-recovery scenarios must be exercised in planned BCDR tests.
Degradation paths typically exploit unfixed defects in target subsystems; vulnerability-handling-and-disclosure procedures identify and remediate the weaknesses an attacker leverages to accelerate subsystem aging.
Unauthorized parameter changes that drive accelerated subsystem aging (over-charging batteries, repeated thermal cycling, propellant-budget waste) are change-management events; documented procedures must govern such modifications and surface anomalous patterns.
ENISA controls
Criticality analysis identifies the mission-critical subsystems whose accelerated degradation would shorten mission lifespan, prioritising protection of the targets IMP-0004 selects.
Incident Recovery Plan with detailed recovery procedures covers the partial-permanent-impairment scenario including post-mortem analysis.
Critical Services Delivery Requirements include resilience under duress and recovery — applicable to permanent-impairment scenarios that shorten lifespan.
Cross-reference controls
T1485 'Data Destruction' addresses permanent data destruction; SPARTA IMP-0004 'Degradation' includes destruction-of-stored-data as one degradation path (calibration tables, mission archives, science buffers). Tactic-aligned but moderate because IMP-0004 emphasises partial degradation while T1485 is full destruction.
T1495 'Firmware Corruption' addresses permanent partial impairment via firmware overwrite/corruption (rendering devices inoperable or with reduced capability); SPARTA IMP-0004 'Degradation' is the parent-level spacecraft equivalent (permanently partially impair use of subsystems via firmware-level damage). Tactic and activity align directly.
T0879 'Damage to Property' is in MITRE ICS impact tactic and addresses adversary actions causing damage and destruction of property to infrastructure/equipment; SPARTA IMP-0004 'Degradation' (permanent partial impairment) is the parent-level spacecraft equivalent. Tactic and activity align directly.
Degradation is the partial case of the same effect and is covered by the same planning obligation.
CP-13 addresses alternative security mechanisms during degradation.
CP-2 addresses mission-continuity planning whose enforcement limits IMP-0004 degradation impact.
IR-4 mitigates IMP-0004 by detecting and responding to degradation indicators.
T2028 'Resource damage' covers attempts to damage a space resource and cause mission loss — direct match to IMP-0004 Degradation's permanent partial impair of subsystems and shortening of spacecraft lifespan.
T2053.005 'Waste of propellant' explicitly covers maliciously consuming satellite propellant to reduce satellite life — direct match to IMP-0004's lifespan-shortening degradation outcomes.
Cite as SafeMode Space, IMP-0004 (SPARTA v3.2).