All techniques
REC-0001.04
ST0001Reconnaissance
sub-technique

Data Bus

Parent: REC-0001

Description

Bus intelligence focuses on which protocols are used (e.g., MIL-STD-1553, SpaceWire, etc.), controller roles, addressing, timings, arbitration, redundancy management, and the location of critical endpoints on each segment. Knowing the bus controller, remote terminal addresses, message identifiers, and schedule tables allows an adversary to craft frames that collide with or supersede legitimate traffic, to starve health monitoring, or to trigger latent behaviors in payload or power systems. Additional details such as line voltages, termination, connector types, harness pinouts, and EMC constraints inform feasibility of injection and disruption techniques. Attackers assemble this picture from ICDs, vendor datasheets, AIT procedures, harness drawings, lab photos, and academic or trade publications that reveal typical configurations. Enumeration of bridges and gateways is especially valuable because they concentrate trust across fault-containment regions and between payload and bus.

Mappings

EU regulation articles

  • eu-space-actArt. 80(3)
    addresses
    high
    direct

    Bus topology, message IDs, schedule tables, and harness pinouts are high-confidentiality design artifacts requiring 80(3)'s information-security categorization.

  • eu-space-actArt. 84(2)
    addresses
    moderate
    inferred

    Art. 84(2)'s comply-with-Annex-VII-5.1 reference is domain-relevant to bus-design exposure, but names no mechanism interdicting the reconnaissance; it is design-discipline governance, not vector interdiction.

  • nis2Art. 21(2)(i)
    addresses
    moderate
    direct

    Bus ICDs, harness drawings, AIT photos, and schedule tables are sensitive engineering assets; access-control + asset-management discipline under Art. 21(2)(i) governs who can extract them from labs, vendor sites, or document repositories.

  • nis2-implAnnex 11.2.1
    addresses
    moderate
    derived

    Access-rights provisioning to bus design repositories and AIT bus-test records is the operational mechanism that bounds who can extract bus topology information.

  • nis2-implAnnex 12.1.1
    addresses
    high
    derived

    Bus-protocol details (1553/SpaceWire timings, addressing, redundancy schemes) are mission-engineering assets; classifying them drives the handling and access-control controls that constrain bus reconnaissance.

ENISA controls

  • Criticality analysis identifies critical bus controllers and endpoints and prioritises their protection, governing rather than actively defending against the data-bus reconnaissance REC-0001.04 performs.

  • Information classification governs the protective marking of the ICDs, harness drawings, and AIT procedures describing bus internals that REC-0001.04 compiles.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, REC-0001.04 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.