All techniques
RD-0002.02
ST0002Resource Development
sub-technique

3rd Party Ground System

Parent: RD-0002

Description

Third-party networks (commercial ground stations, hosted modems, cloud-integrated ground-station services) present attractive stepping-stones: they already have vetted RF chains, globally distributed apertures, and trusted IP space. Adversaries may acquire customer credentials via phishing or purchase, exploit weak vetting to create front-company accounts, or compromise provider portals/APIs to submit schedules, alter front-end settings, or exfiltrate collected data. Because traffic originates from “expected” stations and ASN ranges, misuse blends into normal operations. Multi-tenant risks include configuration bleed-over and shared management planes.

Mappings

EU regulation articles

  • eu-space-actArt. 81(1)
    addresses
    moderate
    direct

    Operator-side IAM under 81(1) extends to credentials issued to third-party-station accounts and APIs — preventing customer-credential abuse on the operator's behalf.

  • eu-space-actArt. 81(4)
    addresses
    moderate
    direct

    Third-party-ground-system compromise (primary: Art. 81(1)) cascades to 81(4) — third-party-account credential audit limits attacker dwell time on commercial portals.

  • eu-space-actArt. 92(1)
    addresses
    high
    direct

    Third-party ground systems are commercial supply-chain components; 92(1)'s contractual information-security obligation governs how the operator constrains third-party-station provider security posture.

  • nis2Art. 21(2)(d)
    addresses
    high
    direct

    Commercial ground stations, hosted modems, and cloud-integrated GS services are direct service providers; Art. 21(2)(d)'s supplier-relationship security obligation governs the trust framework between them and the entity, including provider-portal and shared-management-plane risks.

  • nis2Art. 21(2)(j)
    addresses
    moderate
    direct

    MFA on customer accounts at the third-party provider under Art. 21(2)(j) blocks the credential-driven misuse path the technique relies on for scheduling, front-end configuration, and data egress.

  • nis2Art. 21(3)
    addresses
    high
    direct

    Multi-tenant configuration bleed, weak vetting that admits front companies, and provider-portal exposure are exactly the supplier-specific vulnerabilities Art. 21(3) requires the entity to take into account when reliant on third-party ground services.

  • nis2Art. 23(1)
    triggers obligation
    moderate
    direct

    Compromise of a shared third-party ground network potentially affects multiple operators across Member States; the resulting cross-border impact is reportable under Art. 23(1).

  • nis2Art. 23(2)
    addresses
    moderate
    derived

    Primary mapping to Art. 23(1) treats compromise of a third-party GS as a significant incident. Art. 23(2) timing applies once Art. 23(1) is triggered.

  • nis2Art. 23(3)
    relates to
    moderate
    derived

    Primary mapping to Art. 23(1) treats this as significant. Art. 23(3) significance is met by the cross-border criterion directly: third-party GS providers commonly serve operators across Member States, making cross-border impact structural rather than conditional.

  • nis2Art. 23(4)
    addresses
    moderate
    derived

    Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Awareness typically arrives via the third-party provider's own disclosure to the operator.

  • nis2-implAnnex 5.1.1
    addresses
    high
    derived

    Third-party ground systems are direct suppliers under the supply-chain security policy; the policy is the procedural mechanism that constrains the security posture the entity accepts from its GSaaS or relay provider.

  • nis2-implAnnex 5.1.4
    addresses
    high
    derived

    Supplier-quality requirements (vulnerability assessment, secure-development practices, disclosure obligations) are codified in the entity's supplier selection and contracting; weak third-party hygiene is what makes 3rd-party GS compromise viable.

  • nis2-implAnnex 5.1.6
    addresses
    high
    derived

    Third-party ground-system providers maintain ongoing connections to the entity's mission systems; Annex 5.1.6 monitoring of those providers' security posture and incident-disclosure compliance is essential to detect compromise that could be used as adversary infrastructure against the entity.

  • nis2-implAnnex 5.1.7
    addresses
    moderate
    derived

    Annex 5.1.7 reporting and follow-up are the operational lever that converts third-party-GS monitoring signals into provider replacement, contract amendment or incident-response coordination.

ENISA controls

  • Third-party risk management is the operator-side discipline through which 3rd-party ground systems providing mission services are assessed and monitored.

  • Supplier security management requires 3rd-party ground system operators to demonstrate security management posture before entering the mission's commanding pathway.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, RD-0002.02 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.