Annex I, Part I, (2)(c)
Mapped SPARTA techniques (4)
Techniques referencing this article
Art. (2)(c) is patching-domain relevant (the SDR's update path is the delivery vector abused) but does not interdict the covert-channel injection itself; the control that authenticates and rejects fraudulent waveform/DSP profiles is integrity protection (2)(f) and secure update distribution (Part II 7).
Manufacturer obligation to ensure vulnerabilities can be addressed through security updates extends to SDR firmware and waveform packages whose remediation cadence determines compromise dwell time.
Manufacturer obligation to ensure vulnerabilities can be addressed through security updates implies the integrity of the update mechanism itself; subverting the update path defeats the (2)(c) obligation, so manufacturers must protect that mechanism.
Secure-update mechanisms required by Annex I, Part I, (2)(c) constrain the leverage firmware reconnaissance produces: even with extensive firmware knowledge, the adversary cannot deliver patched/altered images without subverting the manufacturer-required update authentication.