ESA SPACE-SHIELD
T2007.005
enhancement

Malicious supply chain capabilities

Parent: T2007

Description

Obtain or create malicious capabilities inside hardware or software intended to be used in a specific project. Injecting the malicious HW/SW in the right place is difficult, is also difficult being sure that the part will be integrated in a system. (Citation: SRC017)

Mapped SPARTA techniques

3 techniques

  • DE-0012Component CollusionST0006
    addresses
    moderate

    T2007.005 'Malicious supply chain capabilities' covers obtaining/creating malicious capabilities for supply-chain insertion — addresses DE-0012's supply-chain compromise of multiple modules designed to behave cooperatively. SPACE-SHIELD has no component-collusion-specific technique.

  • IA-0001.03Hardware Supply ChainST0003
    addresses
    moderate

    T2007.005 'Malicious supply chain capabilities' specifically covers obtaining malicious capabilities inside hardware/software intended for a specific project — directly aligns with IA-0001.03's hardware Trojans, modified bitstreams, and embedded time-bomb components.

  • T2007.005 'Malicious supply chain capabilities' covers obtaining/creating malicious capabilities for insertion at integration — directly relevant to IA-0012's ATLO-time injection of malicious images, tables, and firmware loads.

Cite as SafeMode Space, space-shield T2007.005.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.