All techniques
LM-0006
ST0007Lateral Movement

Launch Vehicle Interface

Description

During integration and ascent, payloads and the launch vehicle exchange power, discrete lines, and data via umbilicals, separation avionics, and shared EGSE networks. Protections can be reduced or heterogeneous because timelines are tight and responsibilities cross organizations. An attacker positioned on either side (vehicle or payload) can use these commissioning links, health/status queries, time distribution, inhibit lines, separation commands, or telemetry gateways, to inject messages, transfer files, or alter configuration that propagates across the interface. Before fairing close and prior to separation, this brief but high-trust coupling provides a route to move from one platform to the other and to seed artifacts that persist after deployment.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    high
    direct

    Launch vehicle ↔ payload commissioning links carry commands, file transfers, and configuration; (2)(d)'s authentication obligation applies to these high-trust short-duration interfaces.

  • craAnnex I, Part I, (2)(j)
    addresses
    high
    direct

    Umbilicals, separation avionics, and shared EGSE networks are external interfaces (2)(j) requires the product to limit; tight integration timelines are not an exemption from the design obligation.

  • eu-space-actArt. 76(4)
    addresses
    high
    direct

    76(4)(c)(i) explicitly covers the transport, commissioning, launch and early orbit phase (LEOP) — the lifecycle stage LM-0006 attacks via launch-vehicle interfaces.

  • eu-space-actArt. 84(3)
    addresses
    high
    direct

    Launch-vehicle umbilicals and EGSE networks must obey 84(3)'s only-authorized-devices rule; tight integration timelines are not an exemption.

  • nis2Art. 21(2)(d)
    addresses
    high
    direct

    Launch-vehicle operators, range networks, and EGSE suppliers are direct service providers sharing transient but high-trust interfaces with the payload; Art. 21(2)(d)'s supplier-relationship security obligation governs the trust framework over commissioning links and shared lab networks.

  • nis2Art. 21(2)(i)
    addresses
    moderate
    direct

    Umbilicals, EGSE workstations, separation avionics, and inhibit/telemetry-gateway lines are access-controlled assets; Art. 21(2)(i)'s access-control + asset-management obligation governs which roles can issue commissioning-link traffic across the LV/payload boundary.

  • nis2Art. 21(3)
    addresses
    moderate
    derived

    Primary mapping to Art. 21(2)(d) covers the launch-vehicle provider as a supplier of the integration-period interface. Art. 21(3) procedurally extends to scrutiny of the launch provider's secure-development practices for its dispenser and avionics, the lever the spacecraft operator uses for pre-separation interface assurance.

  • nis2-implAnnex 13.3.1
    addresses
    moderate
    derived

    Perimeter and physical-access control over launch-pad EGSE rooms and integration facilities prevents on-site compromise paths through the umbilical and separation-avionics interfaces.

  • nis2-implAnnex 5.1.1
    addresses
    high
    derived

    Launch-vehicle providers, integrators and EGSE network operators are direct suppliers under the supply-chain policy; the policy frames the security expectations imposed on the integration-period interface.

  • nis2-implAnnex 5.1.6
    addresses
    moderate
    derived

    Launch-vehicle providers and EGSE-network operators require Annex 5.1.6 ongoing monitoring because launch-campaign cadence repeatedly exposes the entity to provider posture changes.

  • nis2-implAnnex 5.1.7
    addresses
    moderate
    derived

    Annex 5.1.7 follow-up procedures convert launch-provider monitoring signals into umbilical-handling and EGSE-network protective actions.

  • nis2-implAnnex 6.8.1
    addresses
    moderate
    derived

    Segmentation between launch-vehicle EGSE networks and operator/payload networks bounds the reach of a launch-side compromise into the entity's mission systems.

ENISA controls

  • Third-party risk management covers launch providers and integrators whose cross-organisation responsibilities create the heterogeneity LM-0006 exploits.

  • Supplier security management requires evidence of security posture from launch-vehicle providers and EGSE operators.

Cross-reference controls

  • Supported by two independent derivations that agree, neither of them SafeMode's invention. Through NIST 800-53: SafeMode's curated mapping records LM-0006 against AC-3 Access Enforcement, and CSF 2.0's own crosswalk names that control as an informative reference for PR.AA-05. Through SPARTA: SPARTA's catalog maps LM-0006 to countermeasure CM0038 Segmentation; CM0039 Least Privilege, and that countermeasure's own CSF references include PR.AA-05. Recorded as `addresses` rather than `mitigates` because a CSF subcategory states an outcome to be achieved while the underlying control states the mechanism that achieves it, which is the mechanism-versus-mandate ceiling in decisions entry 15. PR.AA-05 is one of CSF's broader outcomes, so this edge locates the technique within CSF's structure rather than naming a specific defence.

  • Supported by two independent derivations that agree, neither of them SafeMode's invention. Through NIST 800-53: SafeMode's curated mapping records LM-0006 against AC-3 Access Enforcement; SC-7 Boundary Protection, and CSF 2.0's own crosswalk names that control as an informative reference for PR.DS-10. Through SPARTA: SPARTA's catalog maps LM-0006 to countermeasure CM0039 Least Privilege; CM0040 Shared Resource Leakage, and that countermeasure's own CSF references include PR.DS-10. Recorded as `addresses` rather than `mitigates` because a CSF subcategory states an outcome to be achieved while the underlying control states the mechanism that achieves it, which is the mechanism-versus-mandate ceiling in decisions entry 15. PR.DS-10 is one of CSF's broader outcomes, so this edge locates the technique within CSF's structure rather than naming a specific defence.

  • Supported by two independent derivations that agree, neither of them SafeMode's invention. Through NIST 800-53: SafeMode's curated mapping records LM-0006 against AC-3 Access Enforcement; SC-7 Boundary Protection, and CSF 2.0's own crosswalk names that control as an informative reference for PR.IR-01. Through SPARTA: SPARTA's catalog maps LM-0006 to countermeasure CM0038 Segmentation, and that countermeasure's own CSF references include PR.IR-01. Recorded as `addresses` rather than `mitigates` because a CSF subcategory states an outcome to be achieved while the underlying control states the mechanism that achieves it, which is the mechanism-versus-mandate ceiling in decisions entry 15. PR.IR-01 is one of CSF's broader outcomes, so this edge locates the technique within CSF's structure rather than naming a specific defence.

  • Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1021 Remote Services; SafeMode's curated mapping records LM-0006 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because LM-0006 spans both a ground and a space face while the control reaches only one of them.

  • Derived by composition, not from a source that names this pair. D3FEND publishes that Connection Attempt Analysis counters T1021 Remote Services; SafeMode's curated mapping records LM-0006 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because LM-0006 spans both a ground and a space face while the control reaches only one of them.

  • Derived by composition, not from a source that names this pair. D3FEND publishes that Network Traffic Community Deviation counters T1021 Remote Services; SafeMode's curated mapping records LM-0006 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because LM-0006 spans both a ground and a space face while the control reaches only one of them.

  • Derived by composition, not from a source that names this pair. D3FEND publishes that Network Traffic Filtering counters T1021 Remote Services; SafeMode's curated mapping records LM-0006 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because LM-0006 spans both a ground and a space face while the control reaches only one of them.

  • Derived by composition, not from a source that names this pair. D3FEND publishes that Network Traffic Signature Analysis counters T1021 Remote Services; SafeMode's curated mapping records LM-0006 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because LM-0006 spans both a ground and a space face while the control reaches only one of them.

  • Derived by composition, not from a source that names this pair. D3FEND publishes that Protocol Metadata Anomaly Detection counters T1021 Remote Services; SafeMode's curated mapping records LM-0006 as addressing that same adversary behaviour in the space domain. Protocol metadata anomaly detection applies to the telecommand and telemetry link and to internal bus framing, both of which carry structured, baselineable metadata. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because LM-0006 spans both a ground and a space face while the control reaches only one of them.

  • Derived by composition, not from a source that names this pair. D3FEND publishes that Remote Terminal Session Detection counters T1021 Remote Services; SafeMode's curated mapping records LM-0006 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because LM-0006 spans both a ground and a space face while the control reaches only one of them.

  • mitre-attack-enterpriseT1021Remote Services
    addresses
    moderate

    Launch-vehicle-to-spacecraft interfaces (separation connectors, pre-separation data buses, integration ports) are remote services granting cross-vehicle access during the pre-separation phase — direct instance of T1021 'Remote Services' applied to launch-vehicle interfaces.

  • mitre-attack-icsT0886Remote Services
    addresses
    moderate

    Launch-vehicle-to-spacecraft interfaces (separation connectors, pre-separation data buses, integration ports) are remote services granting cross-vehicle access during the pre-separation phase — direct instance of T0886 'Remote Services' applied to launch-vehicle interfaces.

  • The launch vehicle interface carries data and power into the payload during integration and ascent. Mediated subsystem access bounds the reach of anything arriving that way, without addressing the shared EGSE networks the technique also names.

  • nist-80053-rev5AC-2Account Management
    relates to
    moderate

    Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5AC-3Access Enforcement
    mitigates
    moderate

    AC-3 mitigates LM-0006 by enforcing access authorization on launch-vehicle umbilical and EGSE-network interactions.

  • nist-80053-rev5AC-3(13)Attribute-based Access Control
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5AC-4Information Flow Enforcement
    relates to
    moderate

    Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, nasa-bpg, aerospace-tor-2023-02161

    Mapped by SPARTA, not curated by SafeMode Space.

  • Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5AC-4(2)Processing Domains
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5AC-4(23)Modify Non-releasable Information
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5AC-4(24)Internal Normalized Format
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5AC-4(25)Data Sanitization
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5AC-4(26)Audit Filtering Actions
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5AC-4(31)Failed Content Transfer Prevention
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5AC-4(6)Metadata
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5AC-6Least Privilege
    relates to
    moderate

    Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5CA-3Information Exchange
    relates to
    moderate

    Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nasa-bpg, aerospace-tor-2023-02161

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5CA-3(6)Transfer Authorizations
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5CA-3(7)Transitive Information Exchanges
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5CM-7Least Functionality
    relates to
    moderate

    Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5CM-7(5)Authorized Software — Allow-by-exception
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5CM-7(8)Binary or Machine Executable Code
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5PL-8Security and Privacy Architectures
    relates to
    moderate

    Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5PL-8(1)Defense in Depth
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SA-17(7)Structure for Least Privilege
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SA-3System Development Life Cycle
    relates to
    moderate

    Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, aerospace-tor-2023-02161

    Mapped by SPARTA, not curated by SafeMode Space.

  • Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SA-8Security and Privacy Engineering Principles
    relates to
    moderate

    Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nasa-bpg, aerospace-tor-2023-02161

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SA-8(13)Minimized Security Elements
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SA-8(14)Least Privilege
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SA-8(15)Predicate Permission
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SA-8(18)Trusted Communications Channels
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SA-8(19)Continuous Protection
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SA-8(2)Least Common Mechanism
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SA-8(3)Modularity and Layering
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SA-8(4)Partially Ordered Dependencies
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SA-8(5)Efficiently Mediated Access
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SA-8(6)Minimized Sharing
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SA-8(9)Trusted Components
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SC-16(3)Cryptographic Binding
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SC-2(2)Disassociability
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SC-3Security Function Isolation
    relates to
    moderate

    Referenced in: sparta-data, nist-ir-8401, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SC-3(4)Module Coupling and Cohesiveness
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SC-32System Partitioning
    relates to
    moderate

    Referenced in: sparta-data, csf-2-0, nist-ir-8270, nasa-bpg, aerospace-tor-2023-02161

    Mapped by SPARTA, not curated by SafeMode Space.

  • Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SC-39Process Isolation
    relates to
    moderate

    Referenced in: sparta-data, csf-2-0, aerospace-tor-2023-02161

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SC-4Information in Shared System Resources
    relates to
    moderate

    Referenced in: sparta-data, nist-ir-8401, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161

    Mapped by SPARTA, not curated by SafeMode Space.

  • Referenced in: sparta-data, csf-2-0

    Mapped by SPARTA, not curated by SafeMode Space.

  • Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SC-6Resource Availability
    relates to
    moderate

    Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SC-7Boundary Protection
    mitigates
    moderate

    SC-7 mitigates LM-0006 by enforcing boundary protection across launch-vehicle integration networks.

  • nist-80053-rev5SC-7(20)Dynamic Isolation and Segregation
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SC-7(21)Isolation of System Components
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SC-7(29)Separate Subnets to Isolate Functions
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SC-7(5)Deny by Default — Allow by Exception
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SI-17Fail-safe Procedures
    relates to
    moderate

    Referenced in: sparta-data, nist-ir-8323r1, nasa-bpg, aerospace-tor-2023-02161

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SI-4(7)Automated Response to Suspicious Events
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • space-shieldT2039.003Interconnected spacecrafts
    addresses
    moderate

    T2039.003 'Interconnected spacecrafts' covers compromise propagation through spacecraft interconnections — addresses LM-0006's launch-vehicle/payload coupling via umbilicals and shared EGSE during integration and ascent. SPACE-SHIELD has no launch-vehicle-interface-specific lateral-movement technique.

SPARTA countermeasures

Cite as SafeMode Space, LM-0006 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.