All techniques
REC-0001.09
ST0001Reconnaissance
sub-technique

Fault Management

Parent: REC-0001

Description

Fault management (FDIR/autonomy/safing) materials are a prime reconnaissance target because they encode how the spacecraft detects, classifies, and responds to off-nominal states. Adversaries seek trigger thresholds and persistence timers, voting logic, inhibit and recovery ladders, safe-mode entry/exit criteria, command authority in safed states, watchdog/reset behavior, and any differences between flight and maintenance builds. Artifacts include fault trees, FMEAs, autonomy rule tables, safing flowcharts, and anomaly response playbooks. With these, a threat actor can craft inputs that remain just below detection thresholds, stack benign-looking events to cross safing boundaries at tactically chosen times, or exploit recovery windows when authentication, visibility, or redundancy is reduced. Knowledge of what telemetry is suppressed or rate-limited during safing further aids concealment.

Mappings

EU regulation articles

  • eu-space-actArt. 80(3)
    addresses
    high
    direct

    FDIR/autonomy/safing materials (fault trees, FMEAs, autonomy rule tables, safe-mode entry/exit criteria) are high-confidentiality artifacts essential to mission resilience — within 80(3)'s information-security categorization scope.

  • eu-space-actArt. 81(3)
    addresses
    moderate
    direct

    FDIR is a critical function; 81(3)(b)'s access-restriction-to-critical-functions clause restricts access to fault-management documentation and tooling.

  • nis2Art. 21(2)(i)
    addresses
    moderate
    direct

    FDIR docs, autonomy rule tables, FMEAs, and anomaly response playbooks describe how the spacecraft fails safe; they are sensitive operational assets whose disclosure Art. 21(2)(i)'s access-control + asset-management obligation is meant to constrain.

  • nis2-implAnnex 12.1.1
    addresses
    moderate
    derived

    FDIR/safing logic and fault trees are crown-jewel mission assets; their classification level drives the strict need-to-know controls that prevent recon-driven prediction of the spacecraft's safe-mode behaviour.

  • nis2-implAnnex 6.2.1
    addresses
    moderate
    derived

    Fault-management logic is implemented in flight code; the secure-development rules govern access to the FDIR source and its test harnesses, which are the principal leakage paths for safing-behavior reconnaissance.

ENISA controls

  • Criticality analysis identifies the mission-critical fault-management and safing functions that REC-0001.09 seeks to characterise, prioritising them for protection.

  • Classifying FDIR rule tables, safing flowcharts, and fault trees is relevant to limiting REC-0001.09, but information classification and labelling is a governance control and does not actively defend against reconnaissance.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, REC-0001.09 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.