Malicious supply chain capabilities
Parent: T2007
Description
Obtain or create malicious capabilities inside hardware or software intended to be used in a specific project. Injecting the malicious HW/SW in the right place is difficult, is also difficult being sure that the part will be integrated in a system. (Citation: SRC017)
Mapped SPARTA techniques
3 techniques
T2007.005 'Malicious supply chain capabilities' covers obtaining/creating malicious capabilities for supply-chain insertion — addresses DE-0012's supply-chain compromise of multiple modules designed to behave cooperatively. SPACE-SHIELD has no component-collusion-specific technique.
T2007.005 'Malicious supply chain capabilities' specifically covers obtaining malicious capabilities inside hardware/software intended for a specific project — directly aligns with IA-0001.03's hardware Trojans, modified bitstreams, and embedded time-bomb components.
T2007.005 'Malicious supply chain capabilities' covers obtaining/creating malicious capabilities for insertion at integration — directly relevant to IA-0012's ATLO-time injection of malicious images, tables, and firmware loads.
Cite as SafeMode Space, space-shield T2007.005.