Launch Vehicle Interface
Description
During integration and ascent, payloads and the launch vehicle exchange power, discrete lines, and data via umbilicals, separation avionics, and shared EGSE networks. Protections can be reduced or heterogeneous because timelines are tight and responsibilities cross organizations. An attacker positioned on either side (vehicle or payload) can use these commissioning links, health/status queries, time distribution, inhibit lines, separation commands, or telemetry gateways, to inject messages, transfer files, or alter configuration that propagates across the interface. Before fairing close and prior to separation, this brief but high-trust coupling provides a route to move from one platform to the other and to seed artifacts that persist after deployment.
Mappings
EU regulation articles
Launch vehicle ↔ payload commissioning links carry commands, file transfers, and configuration; (2)(d)'s authentication obligation applies to these high-trust short-duration interfaces.
Umbilicals, separation avionics, and shared EGSE networks are external interfaces (2)(j) requires the product to limit; tight integration timelines are not an exemption from the design obligation.
76(4)(c)(i) explicitly covers the transport, commissioning, launch and early orbit phase (LEOP) — the lifecycle stage LM-0006 attacks via launch-vehicle interfaces.
Launch-vehicle umbilicals and EGSE networks must obey 84(3)'s only-authorized-devices rule; tight integration timelines are not an exemption.
Launch-vehicle operators, range networks, and EGSE suppliers are direct service providers sharing transient but high-trust interfaces with the payload; Art. 21(2)(d)'s supplier-relationship security obligation governs the trust framework over commissioning links and shared lab networks.
Umbilicals, EGSE workstations, separation avionics, and inhibit/telemetry-gateway lines are access-controlled assets; Art. 21(2)(i)'s access-control + asset-management obligation governs which roles can issue commissioning-link traffic across the LV/payload boundary.
Primary mapping to Art. 21(2)(d) covers the launch-vehicle provider as a supplier of the integration-period interface. Art. 21(3) procedurally extends to scrutiny of the launch provider's secure-development practices for its dispenser and avionics, the lever the spacecraft operator uses for pre-separation interface assurance.
Perimeter and physical-access control over launch-pad EGSE rooms and integration facilities prevents on-site compromise paths through the umbilical and separation-avionics interfaces.
Launch-vehicle providers, integrators and EGSE network operators are direct suppliers under the supply-chain policy; the policy frames the security expectations imposed on the integration-period interface.
Launch-vehicle providers and EGSE-network operators require Annex 5.1.6 ongoing monitoring because launch-campaign cadence repeatedly exposes the entity to provider posture changes.
Annex 5.1.7 follow-up procedures convert launch-provider monitoring signals into umbilical-handling and EGSE-network protective actions.
Segmentation between launch-vehicle EGSE networks and operator/payload networks bounds the reach of a launch-side compromise into the entity's mission systems.
ENISA controls
Third-party risk management covers launch providers and integrators whose cross-organisation responsibilities create the heterogeneity LM-0006 exploits.
Supplier security management requires evidence of security posture from launch-vehicle providers and EGSE operators.
Cross-reference controls
- csf-2-0PR.AA-05Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of dutiesaddressesmoderate
Supported by two independent derivations that agree, neither of them SafeMode's invention. Through NIST 800-53: SafeMode's curated mapping records LM-0006 against AC-3 Access Enforcement, and CSF 2.0's own crosswalk names that control as an informative reference for PR.AA-05. Through SPARTA: SPARTA's catalog maps LM-0006 to countermeasure CM0038 Segmentation; CM0039 Least Privilege, and that countermeasure's own CSF references include PR.AA-05. Recorded as `addresses` rather than `mitigates` because a CSF subcategory states an outcome to be achieved while the underlying control states the mechanism that achieves it, which is the mechanism-versus-mandate ceiling in decisions entry 15. PR.AA-05 is one of CSF's broader outcomes, so this edge locates the technique within CSF's structure rather than naming a specific defence.
- csf-2-0PR.DS-10The confidentiality, integrity, and availability of data-in-use are protectedaddressesmoderate
Supported by two independent derivations that agree, neither of them SafeMode's invention. Through NIST 800-53: SafeMode's curated mapping records LM-0006 against AC-3 Access Enforcement; SC-7 Boundary Protection, and CSF 2.0's own crosswalk names that control as an informative reference for PR.DS-10. Through SPARTA: SPARTA's catalog maps LM-0006 to countermeasure CM0039 Least Privilege; CM0040 Shared Resource Leakage, and that countermeasure's own CSF references include PR.DS-10. Recorded as `addresses` rather than `mitigates` because a CSF subcategory states an outcome to be achieved while the underlying control states the mechanism that achieves it, which is the mechanism-versus-mandate ceiling in decisions entry 15. PR.DS-10 is one of CSF's broader outcomes, so this edge locates the technique within CSF's structure rather than naming a specific defence.
- csf-2-0PR.IR-01Networks and environments are protected from unauthorized logical access and usageaddressesmoderate
Supported by two independent derivations that agree, neither of them SafeMode's invention. Through NIST 800-53: SafeMode's curated mapping records LM-0006 against AC-3 Access Enforcement; SC-7 Boundary Protection, and CSF 2.0's own crosswalk names that control as an informative reference for PR.IR-01. Through SPARTA: SPARTA's catalog maps LM-0006 to countermeasure CM0038 Segmentation, and that countermeasure's own CSF references include PR.IR-01. Recorded as `addresses` rather than `mitigates` because a CSF subcategory states an outcome to be achieved while the underlying control states the mechanism that achieves it, which is the mechanism-versus-mandate ceiling in decisions entry 15. PR.IR-01 is one of CSF's broader outcomes, so this edge locates the technique within CSF's structure rather than naming a specific defence.
Derived by composition, not from a source that names this pair. D3FEND publishes that Application Protocol Command Analysis counters T1021 Remote Services; SafeMode's curated mapping records LM-0006 as addressing that same adversary behaviour in the space domain. Analysing application-protocol remote commands is directly the telecommand-validation problem: on-board command handlers and the ground command chain both inspect opcode, argument, and sequencing structure before acting. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because LM-0006 spans both a ground and a space face while the control reaches only one of them.
Derived by composition, not from a source that names this pair. D3FEND publishes that Connection Attempt Analysis counters T1021 Remote Services; SafeMode's curated mapping records LM-0006 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because LM-0006 spans both a ground and a space face while the control reaches only one of them.
Derived by composition, not from a source that names this pair. D3FEND publishes that Network Traffic Community Deviation counters T1021 Remote Services; SafeMode's curated mapping records LM-0006 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because LM-0006 spans both a ground and a space face while the control reaches only one of them.
Derived by composition, not from a source that names this pair. D3FEND publishes that Network Traffic Filtering counters T1021 Remote Services; SafeMode's curated mapping records LM-0006 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because LM-0006 spans both a ground and a space face while the control reaches only one of them.
Derived by composition, not from a source that names this pair. D3FEND publishes that Network Traffic Signature Analysis counters T1021 Remote Services; SafeMode's curated mapping records LM-0006 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because LM-0006 spans both a ground and a space face while the control reaches only one of them.
Derived by composition, not from a source that names this pair. D3FEND publishes that Protocol Metadata Anomaly Detection counters T1021 Remote Services; SafeMode's curated mapping records LM-0006 as addressing that same adversary behaviour in the space domain. Protocol metadata anomaly detection applies to the telecommand and telemetry link and to internal bus framing, both of which carry structured, baselineable metadata. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because LM-0006 spans both a ground and a space face while the control reaches only one of them.
Derived by composition, not from a source that names this pair. D3FEND publishes that Remote Terminal Session Detection counters T1021 Remote Services; SafeMode's curated mapping records LM-0006 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because LM-0006 spans both a ground and a space face while the control reaches only one of them.
Launch-vehicle-to-spacecraft interfaces (separation connectors, pre-separation data buses, integration ports) are remote services granting cross-vehicle access during the pre-separation phase — direct instance of T1021 'Remote Services' applied to launch-vehicle interfaces.
Launch-vehicle-to-spacecraft interfaces (separation connectors, pre-separation data buses, integration ports) are remote services granting cross-vehicle access during the pre-separation phase — direct instance of T0886 'Remote Services' applied to launch-vehicle interfaces.
The launch vehicle interface carries data and power into the payload during integration and ascent. Mediated subsystem access bounds the reach of anything arriving that way, without addressing the shared EGSE networks the technique also names.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
AC-3 mitigates LM-0006 by enforcing access authorization on launch-vehicle umbilical and EGSE-network interactions.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, nasa-bpg, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nasa-bpg, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nasa-bpg, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, csf-2-0, nist-ir-8270, nasa-bpg, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, csf-2-0, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, csf-2-0
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8401, nist-ir-8323r1, nist-ir-8441, nist-ir-8270, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
SC-7 mitigates LM-0006 by enforcing boundary protection across launch-vehicle integration networks.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data, nist-ir-8323r1, nasa-bpg, aerospace-tor-2023-02161
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
T2039.003 'Interconnected spacecrafts' covers compromise propagation through spacecraft interconnections — addresses LM-0006's launch-vehicle/payload coupling via umbilicals and shared EGSE during integration and ascent. SPACE-SHIELD has no launch-vehicle-interface-specific lateral-movement technique.
SPARTA countermeasures
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Cite as SafeMode Space, LM-0006 (SPARTA v3.2).