Annex I, Part I, (2)(b)
Mapped SPARTA techniques (2)
Techniques referencing this article
Authentication and access-management (2)(d) addresses DE-0005 by maintaining enforcement through safe-mode rather than relaxing acceptance; secure-by-default config (2)(b) bears on the contingency posture but does not block the safe-mode acceptance vector.
Secure boot, root-of-trust, and verified boot chain are the (2)(b) 'secure by default configuration' realization that bootkit attacks specifically target.