All techniques
RD-0001.02
ST0002Resource Development
sub-technique

Commercial Ground Station Services

Parent: RD-0001

Description

Instead of building dishes, adversaries may rent time on commercial ground networks or cloud-integrated “ground-station-as-a-service.” Access can be obtained legitimately (front companies, weak vetting) or via compromised customer accounts, allowing schedule requests, RF front-end configuration, and data egress through reputable providers. The appeal is speed, global reach, and plausible deniability; the risk to defenders is that traffic originates from expected stations and IP ranges. Misuse may include reconnaissance (passive capture), selective denial (misconfiguration or saturation attempts), or, where authentication is weak, unauthorized commanding.

Mappings

EU regulation articles

  • eu-space-actArt. 92(2)
    relates to
    low
    direct

    Adversaries renting commercial ground-station-as-a-service is mostly outside the operator's control, but 92(2)'s supply-chain risk-reduction strategy includes governance over the operator's own commercial-GSaaS providers — preventing adversary misuse of the operator's contracted ground assets.

  • nis2Art. 21(2)(d)
    addresses
    high
    direct

    Commercial ground-station-as-a-service providers are direct service providers under Art. 21(2)(d); the obligation governs the trust framework, vetting, and security expectations the entity places on those relationships, including how providers police front-company misuse.

  • nis2Art. 21(2)(j)
    addresses
    moderate
    direct

    Multi-factor authentication on customer accounts at commercial GS providers under Art. 21(2)(j) defeats the credential-purchase or weak-vetting routes through which adversaries co-opt legitimate scheduling and front-end configuration.

  • nis2Art. 21(3)
    addresses
    moderate
    direct

    Vetting strength, multi-tenant isolation, and management-plane hygiene at the commercial ground-network provider are the supplier-specific vulnerabilities Art. 21(3) requires the entity to consider when relying on third-party RF infrastructure.

  • nis2-implAnnex 5.1.1
    addresses
    high
    derived

    When the entity itself rents commercial ground-station services, the supply-chain security policy is the procedural framework that constrains how the entity vets, contracts with and audits its GSaaS provider, the same provider an adversary can rent into.

  • nis2-implAnnex 5.1.5
    addresses
    moderate
    derived

    Selection of suppliers under the supply-chain policy must take supplier security quality into account; this includes shared-tenant GSaaS providers whose multi-customer surface enables cross-tenant access.

ENISA controls

  • Third-party risk management on commercial ground station providers is the operator-side discipline that vets and audits the very providers an adversary might rent through.

  • Communications security with strong cryptographic mechanisms renders rented commercial ground-station services ineffective for hostile commanding without mission keys, but RD-0001.02's defining act is renting station access, which the control does not interdict; the rented station retains collection utility. The control blunts downstream commanding rather than the defining vector, so the relationship is addresses.

Cross-reference controls

  • mitre-attack-enterpriseT1583Acquire Infrastructure
    relates to
    moderate

    Mapped by SPARTA, not curated by SafeMode Space.

  • mitre-attack-enterpriseT1583.006Web Services
    addresses
    moderate

    AWS Ground Station and similar SaaS-style ground-segment offerings register as web services; T1583.006 'Web Services' covers this specific procurement model, downgraded because not all commercial ground-station services are web-services-shaped (some are traditional contracts).

  • nist-80053-rev5PM-16Threat Awareness Program
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5RA-10Threat Hunting
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5RA-3Risk Assessment
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5RA-3(2)Use of All-source Intelligence
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5RA-3(3)Dynamic Threat Awareness
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SA-3System Development Life Cycle
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SA-8Security and Privacy Engineering Principles
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SI-4(24)Indicators of Compromise
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • nist-80053-rev5SR-8Notification Agreements
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • T1583.005 'Rent ground segment as a service' is the direct counterpart of RD-0001.02 Commercial Ground Station Services — both describe renting cloud-integrated ground services rather than building.

SPARTA countermeasures

Cite as SafeMode Space, RD-0001.02 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.