All techniques
RD-0002.01
ST0002Resource Development
sub-technique

Mission-Operated Ground System

Parent: RD-0002

Description

Compromising a mission’s own ground system grants the adversary preconfigured access to TT&C and automation. High-value targets include operator workstations, mission control servers, procedure libraries, scheduler/orchestration services, key-loading tools and HSMs, antenna control systems, timing/distribution, and RF modems/baseband units. Typical paths: phishing an operator or contractor, abusing remote-support channels, pivoting from enterprise IT to ops, exploiting unpatched services on enclave gateways, or harvesting credentials from poorly segmented test environments. Once inside, an actor can stage malicious procedures, alter rate/size limits, manipulate pass schedules, downgrade authentication in maintenance modes, or quietly siphon telemetry and ephemerides to refine later attacks.

Mappings

EU regulation articles

  • eu-space-actArt. 81(1)
    addresses
    high
    direct

    Compromise of the mission's own ground system (operator workstations, mission control servers, key-loading tools, antenna control) is exactly what 81(1)'s identity-and-access-management protocols defend.

  • eu-space-actArt. 81(3)
    mitigates
    moderate
    direct

    81(3)(a)'s safeguarding of access to the ground segment and centres for control of the space segment, combined with (b) restricting access to critical assets/functions, mitigates lateral spread post-initial-access into mission ground.

  • eu-space-actArt. 81(4)
    addresses
    moderate
    direct

    Mission-ground-system compromise (primary: Art. 81(1)) cascades to 81(4) — operator workstation and HSM credential audit is part of the lifecycle discipline.

  • eu-space-actArt. 83(1)
    addresses
    high
    direct

    Continuous monitoring under 83(1), and ground-station detection mechanisms under 83(2) (Annex VII point 4), directly address detection of mission-ground-system intrusion.

  • nis2Art. 21(2)(b)
    addresses
    high
    derived

    Adversary control of the entity's own ground system — operator workstations, MCC, schedulers, key-loading tools — is a high-severity incident the entity's incident-handling capability under Art. 21(2)(b) must detect via pre-positioned-tooling, log-suppression, and procedure-tampering signals.

  • nis2Art. 21(2)(i)
    addresses
    high
    direct

    Operator workstations, mission control servers, procedure libraries, scheduler/orchestration services, key-loading tools/HSMs, and timing distribution are the precise asset class Art. 21(2)(i)'s access-control + asset-management obligation governs.

  • nis2Art. 21(2)(j)
    mitigates
    moderate
    direct

    MFA on operator and admin accounts under Art. 21(2)(j) defeats the dominant phishing-and-pivot path through which mission-operated ground systems are compromised.

  • nis2Art. 23(1)
    triggers obligation
    high
    direct

    Compromise of the mission's own ground system causes severe operational disruption to the provision of services, meeting the Art. 23(3) significance criteria and triggering the Art. 23(1) reporting regime.

  • nis2Art. 23(2)
    addresses
    high
    derived

    Primary mapping to Art. 23(1) treats compromise of the mission-operated GS (as adversary infrastructure) as a significant incident. Art. 23(2) timing applies once Art. 23(1) is triggered.

  • nis2Art. 23(3)
    relates to
    moderate
    derived

    Primary mapping to Art. 23(1) treats this as significant. Art. 23(3) significance attaches to the operational-disruption potential a compromised mission-operated GS introduces; cross-border impact is conditional on the GS supporting multi-Member-State customers.

  • nis2Art. 23(4)
    addresses
    moderate
    derived

    Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Awareness typically lags GS compromise by days to weeks.

  • nis2-implAnnex 11.2.1
    addresses
    moderate
    derived

    Access-rights provisioning hygiene at the mission-operated GS bounds the population the attacker can impersonate after foothold.

  • nis2-implAnnex 11.7.1
    addresses
    high
    derived

    Multi-factor authentication on operator workstations and TT&C automation is the authentication procedure that prevents harvested or replayed credentials from converting into live commanding access.

  • nis2-implAnnex 3.2.1
    addresses
    moderate
    derived

    Monitoring-and-logging procedures are the detective control that surfaces a compromised mission-operated GS as adversary infrastructure before it is used for mission-impact actions.

  • nis2-implAnnex 6.8.1
    addresses
    high
    direct

    Network segmentation is the precise architectural control that limits lateral mobility inside a compromised mission-operated ground system; the implementing regulation requires the entity to segment systems into networks or zones based on risk assessment.

ENISA controls

  • Access control with least privilege, separation of duties, and four-eyes principle governs who can access mission-operated ground systems and how, addressing this technique directly.

  • Multi-factor authentication on mission-control accounts limits credential-only compromise of the mission-operated ground system.

  • Intrusion detection and prevention with traffic baselines for mission-operated ground systems detects the compromise activity that defines this sub-technique.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, RD-0002.01 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.