cra

Annex I, Part I, (2)(c)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (4)

Techniques referencing this article

  • EXF-0006.01Software Defined RadioST0008
    addresses
    moderate
    inferred

    Art. (2)(c) is patching-domain relevant (the SDR's update path is the delivery vector abused) but does not interdict the covert-channel injection itself; the control that authenticates and rejects fraudulent waveform/DSP profiles is integrity protection (2)(f) and secure update distribution (Part II 7).

  • IA-0002Compromise Software Defined RadioST0003
    addresses
    moderate
    derived

    Manufacturer obligation to ensure vulnerabilities can be addressed through security updates extends to SDR firmware and waveform packages whose remediation cadence determines compromise dwell time.

  • IA-0007.01Compromise On-Orbit UpdateST0003
    addresses
    high
    derived

    Manufacturer obligation to ensure vulnerabilities can be addressed through security updates implies the integrity of the update mechanism itself; subverting the update path defeats the (2)(c) obligation, so manufacturers must protect that mechanism.

  • REC-0001.02FirmwareST0001
    addresses
    moderate
    derived

    Secure-update mechanisms required by Annex I, Part I, (2)(c) constrain the leverage firmware reconnaissance produces: even with extensive firmware knowledge, the adversary cannot deliver patched/altered images without subverting the manufacturer-required update authentication.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.