3rd-Party Spacecraft
Parent: RD-0002
Description
By compromising another operator’s spacecraft, or a hosted payload, an adversary can gain proximity, sensing, and relay capabilities that are costly to build from scratch and difficult to attribute. With control of an on-orbit asset, the actor may conduct local spectrum measurement and traffic analysis, attempt selective interference or spoofing at short range, or probe crosslinks and gateways where payload networks bridge to buses. In rideshare or hosted-payload contexts, weak segmentation and shared ground paths can provide insight into neighboring missions. More aggressive scenarios include remote proximity operations (RPO) to achieve advantageous geometry; however, physical grappling, docking, or exposure of debug/test interfaces is highly specialized and rare, with significant safety, legal, and tracking implications. Realistic attacker goals emphasize adjacency for RF leverage, covert relay, or data theft rather than mechanical capture.
Mappings
EU regulation articles
91(3)'s pre-defined-agreements-with-third-party-entities clause (for hosted-payload contexts) governs how operators coordinate with the third-party spacecraft owner during compromise scenarios affecting proximity assets.
When the third-party spacecraft is the operator's hosted-payload host or rideshare neighbor, 92(1)'s supply-chain governance covers the contractual relationship that affects access to neighboring assets.
When a hosted-payload bus operator or rideshare host is in the entity's supplier graph, Art. 21(2)(d)'s supplier-relationship security obligation governs the trust framework around weak segmentation and shared ground paths the technique exploits.
Cross-organisation segmentation and key-management practices at the third-party operator are the supplier-specific vulnerabilities Art. 21(3) requires the entity to consider when its mission rides shared infrastructure.
Compromise of a third-party operator's spacecraft acting as proxy or relay engages the entity's supply-chain policy when the entity uses that operator's services or shares a bus/payload; the policy bounds what the entity accepts from the host operator.
ENISA controls
Third-party risk management explicitly covers other operators whose spacecraft share infrastructure with the host mission.
Supplier security management on co-hosted spacecraft providers establishes the audit and standards baseline that limits compromise propagation.
Cross-reference controls
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
SA-9 addresses contractual posture for external spacecraft hosting/sharing arrangements.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
SR-3 addresses supply-chain and partner controls bearing on third-party-spacecraft compromise risk.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
T1584.002 'Compromise Satellite(s)' is the direct counterpart of RD-0002.03 3rd-Party Spacecraft — both describe gaining control of another operator's spacecraft for proximity, sensing, or relay.
SPARTA countermeasures
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Cite as SafeMode Space, RD-0002.03 (SPARTA v3.2).