The contradiction there is between “catastrophic failure” and “program ... to [do]”. Catastrophic failure implies that control is lost.
I was thinking of a separate control system designed to de-orbit the device in the event of primary control system failure.
Sorry if I did not make that clear.