All techniques
REC-0001
ST0001Reconnaissance

Gather Spacecraft Design Information

Description

Threat actors seek a coherent picture of the spacecraft and its supporting ecosystem to reduce uncertainty and plan follow-on actions. Useful design information spans avionics architecture, command and data handling, comms and RF chains, power and thermal control, flight dynamics constraints, payload-to-bus interfaces, redundancy schemes, and ground segment dependencies. Artifacts often include ICDs, block diagrams, SBOMs and toolchains, test procedures, AIT travelers, change logs, and “as-built” versus “as-flown” deltas. Adversaries combine open sources (papers, patents, theses, conference slides, procurement documents, FCC/ITU filings, marketing sheets) with gray sources (leaked RFP appendices, vendor manuals, employee resumes, social posts) to infer single points of failure, unsafe modes, or poorly defended pathways between space, ground, and supply chain. The output of this activity is not merely a document set but a working mental model and, often, a lab replica that enables rehearsal, timing studies, and failure-mode exploration.

Mappings

EU regulation articles

  • eu-space-actArt. 80(3)
    addresses
    high
    direct

    Spacecraft design information (avionics architecture, ICDs, SBOMs, AIT travelers) is exactly what 80(3) requires the operator to categorize by confidentiality, integrity, authenticity, and availability needs.

  • eu-space-actArt. 81(6)
    addresses
    moderate
    direct

    The identity-and-access-management protocols required by 81(6) protect design documentation and engineering artifacts from unauthorized access — the precise control that defeats reconnaissance against operator-held design info.

  • eu-space-actArt. 92(1)
    addresses
    moderate
    direct

    Design info shared with supplier manufacturers is a supply-chain attack surface; 92(1)'s contracts-must-include-information-security-requirements obligation governs how the operator constrains supplier disclosure.

  • nis2Art. 21(2)(i)
    addresses
    high
    direct

    ICDs, block diagrams, SBOMs, AIT travelers, and as-built/as-flown deltas are sensitive engineering assets; access-control policies and asset-management discipline under Art. 21(2)(i) govern who can reach them and how leakage from contractor laptops, RFP appendices, or vendor manuals is constrained.

  • nis2-implAnnex 10.1.1
    addresses
    moderate
    derived

    Personnel handling sensitive design information must be subject to NIS-aware HR security obligations because the recon path frequently runs through engineers and contractors carrying ICDs and SBOMs on personal devices or to RFP appendices.

  • nis2-implAnnex 11.2.1
    addresses
    moderate
    direct

    Provision, modification, removal and documentation of access rights to design repositories, ICD vaults, AIT records and contractor data rooms is the operational mechanism that prevents unauthorized retrieval of the engineering corpus the technique targets.

  • nis2-implAnnex 12.1.1
    addresses
    high
    direct

    ICDs, block diagrams, SBOMs and AIT travelers are the precise category of mission-critical information assets that must receive a classification level under the asset-classification framework so that downstream handling and access controls can be calibrated to their sensitivity.

  • nis2-implAnnex 12.2.1
    addresses
    high
    direct

    Handling-of-assets policy is the procedural lever that constrains how design information moves between primes, subs, partner missions and contractor laptops, which is exactly the leakage surface a design-reconnaissance adversary exploits.

ENISA controls

  • Operator-side threat modelling explicitly anticipates the adversary's intelligence-gathering on architecture, attack surface, and lifecycle artefacts that REC-0001 collects.

  • Criticality analysis identifying mission-critical functions, components, and data flows prioritises protection of what REC-0001 most values, but criticality analysis is a governance control and does not itself actively defend against design-information gathering.

  • Classifying and labelling design artefacts gates them out of the open sources REC-0001 mines and is relevant, but information classification and labelling is a governance control and does not actively defend against reconnaissance.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, REC-0001 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.