Article 78
Risk assessments
1. Throughout the life cycle of space missions, Union space operators, shall:
(a) identify and assess, on a continuous basis, all sources of risks;
(b) regularly review the identified risks;
(c) identify cybersecurity and physical vulnerabilities and incidents and analyse, in view of the risk assessment referred to in paragraph 2, when such vulnerabilities cannot be fixed or mitigated immediately;
(d) establish dedicated risk treatment plans for all the cybersecurity vulnerabilities identified which create a risk above the level of risk referred to in Article 76(2), point (b).
2. Union space operators shall carry out risk assessments in accordance with point 1, of Annex VII.
3. The Commission is empowered to adopt delegated acts, in accordance with Article 113, to supplement this Regulation by:
(a) establishing, for the purposes of the risk scenarios referred to in point 1.4, point (f), of Annex VII, the criteria for the identification of:
(i) critical assets, critical functions, critical operations and critical stages, throughout the lifecycle of space missions, for which Union space operators shall develop security risk scenarios;
(ii) critical assets and critical functions referred to in Article 79(1), first subparagraph, for which the entities applying a simplified risk management shall develop security risk scenarios;
(b) developing risk scenarios that are tailored to the risks addressed by Union space operators, and respectively entities applying a simplified risk management;
(c) establishing a minimal list of security objectives, including the risk levels to be taken into account;
(d) developing the criteria and the methodology to ensure the comparability of risk assessments, to facilitate the supervisory activities (‘supervisory reviews’) of competent authorities;
(e) develop threat modelling methods to support the risk assessments for different segments and systems of space infrastructure;
(f) develop risk treatment measures to be applied by the Union space operators.
Warning: Cannot modify header information - headers already sent by (output started at /var/www/html/article.php:8) in /var/www/html/script/loginauth.php on line 163