All techniques
REC-0002.02
ST0001Reconnaissance
sub-technique

Organization

Parent: REC-0002

Description

Threat actors map the human and institutional terrain surrounding the mission to find leverage for phishing, credential theft, invoice fraud, or supply-chain compromise. Targeted details include the owner/operator, prime and subcontractors (bus, payload, ground, launch), key facilities and labs, cloud/SaaS providers, organizational charts, distribution lists, and role/responsibility boundaries for operations, security, and engineering. The objective is to identify who can approve access, who can move money, who holds admin roles on ground and cloud systems, and which vendors maintain remote access for support. Understanding decision chains also reveals when changes control boards meet, when ops handovers occur, and where a single compromised account could bridge enclaves.

Mappings

EU regulation articles

  • eu-space-actArt. 77(2)
    addresses
    high
    direct

    Mapping of personnel, prime/sub relationships, role/responsibility boundaries, and admin roles is what 77(2)'s human-resources security policy governs — vetting, checks, and disciplinary processes limit the leakage of role-based information.

  • eu-space-actArt. 92(1)
    addresses
    moderate
    direct

    The contractual mapping of primes, subs, MSPs, and partners is exactly the supplier ecosystem 92(1) requires the operator to govern through supply-chain security contracts.

  • nis2Art. 21(2)(g)
    addresses
    moderate
    direct

    Org-chart enumeration feeds spear-phishing, invoice-fraud, and credential-theft pretexts; basic cyber hygiene practices and cybersecurity training under Art. 21(2)(g) are the obligation that builds resistance in operators, finance, and engineering staff.

  • nis2Art. 21(2)(i)
    addresses
    moderate
    direct

    Access-control policies under Art. 21(2)(i) are how the entity decides who holds admin/approval/funding-routing roles in the first place; least-privilege design limits the value of any single account a recon-driven phish could bridge.

  • nis2-implAnnex 10.1.1
    addresses
    moderate
    derived

    HR-security obligations bind employees to discipline around exposing organizational structure, escalation paths and project assignments — the data on which org-mapping reconnaissance depends.

  • nis2-implAnnex 8.1.1
    addresses
    high
    direct

    Mapping the human and institutional terrain to enable phishing, credential theft and invoice fraud is precisely the threat surface the cyber-hygiene awareness obligation addresses; the implementing regulation requires the entity to ensure employees understand the risks they expose through public profiles and routine communication.

ENISA controls

  • An insider-threat programme is relevant to the personnel-security leverage REC-0002.02 maps toward and deters downstream insider recruitment, but it does not actively defend against the external reconnaissance of organisational structure itself.

  • Cybersecurity awareness and training addresses the human attack vector that organisational reconnaissance (REC-0002.02) enables, a program relevant to the technique rather than an active defense against the mapping.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, REC-0002.02 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.