All techniques
IMP-0006
ST0009Impact

Theft

Description

Threat actors may attempt to steal the data that is being gathered, processed, and sent from the victim spacecraft. Many spacecraft have a particular purpose associated with them and the data they gather is deemed mission critical. By attempting to steal this data, the mission, or purpose, of the spacecraft could be lost entirely.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    moderate
    direct

    Strict authentication and access-management mechanisms restrict who can access the data stores and downlink channels theft would target — within (2)(d)'s appropriate-control-mechanisms scope.

  • craAnnex I, Part I, (2)(e)
    addresses
    high
    direct

    Stealing the data the spacecraft gathers, processes, and sends is the canonical confidentiality breach (2)(e) requires the product to protect against via state-of-the-art encryption at rest and in transit.

  • craArt. 14(10)
    relates to
    moderate
    direct

    Theft severe-incident notification (primary mapping: Art. 14(3)) follows the format and procedures specified by (14)(10)'s implementing acts.

  • craArt. 14(3)
    triggers obligation
    moderate
    direct

    Theft of mission-critical data affects confidentiality of important data — meeting the 14(5)(a) severe-incident threshold and triggering the manufacturer's 14(3) notification obligations.

  • craArt. 14(4)
    addresses
    high
    direct

    Theft severe-incident notification (primary mapping: Art. 14(3)) cascades to (14)(4)'s timing schedule for the confidentiality-impact case.

  • craArt. 14(9)
    relates to
    moderate
    direct

    Theft severe incidents (primary mapping: Art. 14(3)) may justify delayed dissemination to avoid further compromise of stolen-data scope or to coordinate with law enforcement; (14)(9) governs.

  • eu-space-actArt. 80(3)
    addresses
    moderate
    inferred

    Art. 80(3)'s information categorization is domain-relevant to theft (it drives encryption policy), but categorization itself does not interdict the exfiltration.

  • eu-space-actArt. 81(1)
    addresses
    moderate
    direct

    Strict authentication and access-management mechanisms under 81(1) restrict who can access data stores and downlink channels theft would target.

  • eu-space-actArt. 81(4)
    addresses
    moderate
    direct

    Theft-impact (primary: Art. 81(1)) is mitigated by 81(4)'s credential audit and revocation lifecycle that limits the population that can access the data stores theft targets.

  • eu-space-actArt. 85(1)
    addresses
    high
    direct

    Stealing mission-critical data is the canonical confidentiality breach 85(1)'s cryptographic concept addresses — encryption at rest and in transit limits exfiltration value.

  • eu-space-actArt. 93(3)
    addresses
    high
    direct

    Theft significant-incident reporting (primary: Art. 93(6)) cascades to 93(3) — confidentiality-affecting incidents under NIS2 essential-entity status route via CSIRTs.

  • eu-space-actArt. 93(4)
    relates to
    moderate
    direct

    Theft reporting (primary: Art. 93(6)) relates to 93(4) — confidentiality-affecting incidents trigger NIS2 Art. 23 in parallel.

  • eu-space-actArt. 93(6)
    triggers obligation
    moderate
    direct

    Theft of mission-critical data can cause considerable damage to natural or legal persons (93(6)(b)) and may also disrupt the affected service — triggering 93(1)/(2) reporting.

  • eu-space-actArt. 93(7)
    addresses
    moderate
    direct

    Theft reporting (primary: Art. 93(6)) cascades to 93(7) — confidentiality-impacting incidents follow the 12h/24h/72h timing schedule.

  • eu-space-actArt. 93(8)
    relates to
    moderate
    direct

    Theft reporting (primary: Art. 93(6)) relates to 93(8) — implementing-acts on content/templates govern theft-incident report formats.

  • nis2Art. 21(2)(b)
    addresses
    high
    derived

    Confirmed exfiltration of mission-critical data is a significant incident the entity's incident-handling capability under Art. 21(2)(b) must detect (anomalous downlinks, unscheduled playbacks) and contain.

  • nis2Art. 21(2)(h)
    addresses
    high
    direct

    Art. 21(2)(h) requires cryptography and, where appropriate, encryption policies covering payload and mission data; it addresses theft of mission data by mandating encryption in transit and at rest, while the deployed confidentiality controls, not the policy obligation, are what actually deny the adversary the content.

  • nis2Art. 21(2)(i)
    addresses
    moderate
    direct

    Mission-critical data is an asset whose access must be governed by access-control policies and asset-management discipline under Art. 21(2)(i); least-privilege role design constrains who can stage exfiltration.

  • nis2Art. 23(1)
    triggers obligation
    high
    direct

    Theft of mission-critical data affects natural or legal persons who depend on those products and meets the Art. 23(3)(b) significance criterion; Art. 23(1) notification is triggered.

  • nis2Art. 23(2)
    addresses
    moderate
    derived

    Primary mapping to Art. 23(1) treats theft of mission data as a significant incident. Art. 23(2) timing applies once Art. 23(1) is triggered.

  • nis2Art. 23(3)
    relates to
    moderate
    derived

    Primary mapping to Art. 23(1) treats theft as significant. Art. 23(3) significance test is met by the financial-loss criterion (commercial mission data) and frequently the cross-border criterion (constellation data routinely covers multi-Member-State customers).

  • nis2Art. 23(4)
    addresses
    high
    derived

    Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Theft is often detected via downstream IOC matches; awareness can lag exfil by significant time.

  • nis2-implAnnex 11.2.1
    addresses
    moderate
    derived

    Access-rights provisioning bounds the population that can read or copy mission-critical datasets; over-broad access is the leverage data-theft attacks exploit.

  • nis2-implAnnex 12.1.1
    addresses
    high
    derived

    Mission data is the principal target of theft attacks; the asset-classification obligation is the foundational control that drives the encryption, access and storage controls determining whether theft is feasible at all.

  • nis2-implAnnex 12.2.1
    addresses
    high
    direct

    Asset-handling policy covers the entire life cycle of mission data (acquisition, use, storage, transportation, disposal); strict handling discipline is the operational lever that resists theft along every stage of the data-distribution chain.

  • nis2-implAnnex 6.7.1
    addresses
    moderate
    derived

    Network-security obligations cover the protection of mission data in transit (encryption, integrity, egress monitoring), reducing the value of intercepted or exfiltrated traffic offline.

ENISA controls

  • Communications security with confidentiality preservation during transmission directly defeats interception of mission-critical data on the downlink path.

  • Data encryption per availability/integrity/confidentiality requirements covers the mission-critical payload data IMP-0006 attempts to steal.

  • Information classification and labelling governs the protection requirements and acceptable use of the mission-critical data IMP-0006 targets, establishing handling rules rather than actively preventing exfiltration.

  • DLP solutions safeguarding information assets from unauthorised access and disclosure are the named control against bulk theft of mission-critical data.

Cross-reference controls

  • d3fendD3-CFContent Filtering
    addresses
    low

    Derived by composition, not from a source that names this pair. D3FEND publishes that Content Filtering counters T1041 Exfiltration Over C2 Channel; SafeMode's curated mapping records IMP-0006 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because IMP-0006 spans both a ground and a space face while the control reaches only one of them.

  • d3fendD3-CMContent Modification
    addresses
    low

    Derived by composition, not from a source that names this pair. D3FEND publishes that Content Modification counters T1041 Exfiltration Over C2 Channel; SafeMode's curated mapping records IMP-0006 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because IMP-0006 spans both a ground and a space face while the control reaches only one of them.

  • d3fendD3-CQContent Quarantine
    addresses
    low

    Derived by composition, not from a source that names this pair. D3FEND publishes that Content Quarantine counters T1041 Exfiltration Over C2 Channel; SafeMode's curated mapping records IMP-0006 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because IMP-0006 spans both a ground and a space face while the control reaches only one of them.

  • Derived by composition, not from a source that names this pair. D3FEND publishes that Client-server Payload Profiling counters T1041 Exfiltration Over C2 Channel; SafeMode's curated mapping records IMP-0006 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because IMP-0006 spans both a ground and a space face while the control reaches only one of them.

  • d3fendD3-DFDecoy File
    addresses
    low

    Derived by composition, not from a source that names this pair. D3FEND publishes that Decoy File counters T1041 Exfiltration Over C2 Channel; SafeMode's curated mapping records IMP-0006 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because IMP-0006 spans both a ground and a space face while the control reaches only one of them.

  • d3fendD3-FEFile Encryption
    addresses
    low

    Derived by composition, not from a source that names this pair. D3FEND publishes that File Encryption counters T1041 Exfiltration Over C2 Channel; SafeMode's curated mapping records IMP-0006 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because IMP-0006 spans both a ground and a space face while the control reaches only one of them.

  • Derived by composition, not from a source that names this pair. D3FEND publishes that Local File Permissions counters T1041 Exfiltration Over C2 Channel; SafeMode's curated mapping records IMP-0006 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because IMP-0006 spans both a ground and a space face while the control reaches only one of them.

  • Derived by composition, not from a source that names this pair. D3FEND publishes that Network Traffic Community Deviation counters T1041 Exfiltration Over C2 Channel; SafeMode's curated mapping records IMP-0006 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because IMP-0006 spans both a ground and a space face while the control reaches only one of them.

  • Derived by composition, not from a source that names this pair. D3FEND publishes that Network Traffic Filtering counters T1041 Exfiltration Over C2 Channel; SafeMode's curated mapping records IMP-0006 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because IMP-0006 spans both a ground and a space face while the control reaches only one of them.

  • Derived by composition, not from a source that names this pair. D3FEND publishes that Network Traffic Signature Analysis counters T1041 Exfiltration Over C2 Channel; SafeMode's curated mapping records IMP-0006 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because IMP-0006 spans both a ground and a space face while the control reaches only one of them.

  • Derived by composition, not from a source that names this pair. D3FEND publishes that Per Host Download-Upload Ratio Analysis counters T1041 Exfiltration Over C2 Channel; SafeMode's curated mapping records IMP-0006 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because IMP-0006 spans both a ground and a space face while the control reaches only one of them.

  • Derived by composition, not from a source that names this pair. D3FEND publishes that Protocol Metadata Anomaly Detection counters T1041 Exfiltration Over C2 Channel; SafeMode's curated mapping records IMP-0006 as addressing that same adversary behaviour in the space domain. Protocol metadata anomaly detection applies to the telecommand and telemetry link and to internal bus framing, both of which carry structured, baselineable metadata. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because IMP-0006 spans both a ground and a space face while the control reaches only one of them.

  • Derived by composition, not from a source that names this pair. D3FEND publishes that Remote File Access Mediation counters T1041 Exfiltration Over C2 Channel; SafeMode's curated mapping records IMP-0006 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because IMP-0006 spans both a ground and a space face while the control reaches only one of them.

  • mitre-attack-enterpriseT1041Exfiltration Over C2 Channel
    addresses
    moderate

    MITRE Enterprise has no impact-tactic data-theft technique; the theft outcome is captured through the exfiltration mechanism (T1041 Exfiltration Over C2 Channel and related). T1041 covers data theft via the legitimate C2 channel — the primary mechanism for SPARTA IMP-0006 'Theft' (steal mission-critical data via spacecraft downlink). Cross-tactic moderate (exfiltration vs impact) honors MITRE's separation of exfil-mechanism from impact-outcome where SPARTA combines them.

  • mitre-attack-icsT0882Theft of Operational Information
    addresses
    high

    T0882 'Theft of Operational Information' is in MITRE ICS impact tactic and addresses adversary theft of operational information from production environments — exact title-and-concept match for SPARTA IMP-0006 'Theft' (steal mission-critical data). Tactic and activity align directly. Notable: this is a tactic-aligned high anchor in MITRE ICS where MITRE Enterprise had cross-tactic moderate to T1041 — ICS uniquely models data theft as an impact-tactic outcome rather than separating it from the exfiltration mechanism.

  • nist-80053-rev5AC-23Data Mining Protection
    mitigates
    moderate

    AC-23 mitigates IMP-0006 by limiting bulk extraction that data-mining-style theft requires.

  • nist-80053-rev5AC-3Access Enforcement
    mitigates
    moderate

    AC-3 mitigates IMP-0006 by enforcing access authorization on data stores theft would target.

  • nist-80053-rev5AC-4Information Flow Enforcement
    mitigates
    high

    AC-4 mitigates IMP-0006 by constraining information flow that theft would otherwise traverse.

  • nist-80053-rev5AU-12Audit Record Generation
    addresses
    moderate

    AU-12 addresses audit-record generation on data access whose review surfaces theft attempts.

  • nist-80053-rev5IR-4Incident Handling
    addresses
    moderate

    IR-4 mitigates IMP-0006 by detecting and responding to theft indicators.

  • nist-80053-rev5SC-13Cryptographic Protection
    mitigates
    moderate

    SC-13 mitigates IMP-0006 by mandating cryptographic protection on stolen-while-encrypted data so theft yields ciphertext.

  • SC-8 mitigates IMP-0006 by protecting data confidentiality on transmission paths theft uses.

  • nist-80053-rev5SC-8(1)Cryptographic Protection
    mitigates
    moderate

    SC-8(1) mitigates IMP-0006 by ensuring transmission cryptographic protection.

  • space-shieldT2018Data from link eavesdropping
    addresses
    moderate

    T2018 'Data from link eavesdropping' covers collecting data transmitted over channels — direct match to IMP-0006's theft of mission-critical data being gathered, processed, and sent from the victim spacecraft.

  • space-shieldT2022Exfiltration Over TM Channel
    addresses
    moderate

    T2022 'Exfiltration Over TM Channel' covers malicious software using the TM channel to exfiltrate data — addresses IMP-0006's theft outcome where stolen mission data exits via the TM downlink path.

Cite as SafeMode Space, IMP-0006 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.