cra

Annex I, Part I, (2)(l)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (30)

Techniques referencing this article

  • DE-0001Disable Fault ManagementST0006
    addresses
    high
    direct

    FDIR alerts and event routing ARE the security-related information channel; suppressing them is the precise failure (2)(l) requires recording and monitoring of internal activity to prevent.

  • DE-0002.03Inhibit Spacecraft FunctionalityST0006
    addresses
    moderate
    direct

    (2)(l) requires recording and monitoring of internal activity, including modification of services or functions — the telemetry-publisher reconfiguration that (2)(l) is meant to surface as security-related information.

  • DE-0003On-Board Values ObfuscationST0006
    addresses
    moderate
    direct

    The values being obfuscated (counters, flags, mode indicators) are the very recording fields (2)(l) requires the product to maintain for security-relevant internal activity monitoring.

  • The VCC is a primary recording channel for command-acceptance activity; (2)(l)'s record-and-monitor requirement is precisely defeated when the counter is biased or hidden.

  • DE-0003.02Rejected Command CounterST0006
    addresses
    high
    direct

    Rejection counts and reason codes are core security-monitoring telemetry — exactly the recording fields (2)(l) requires for surfacing failed-authentication and probe activity.

  • DE-0003.05Command Receiver Lock ModesST0006
    addresses
    moderate
    direct

    Lock-status indicators and counters are recording fields whose tampering defeats (2)(l)'s monitoring obligation.

  • DE-0003.06Telemetry Downlink ModesST0006
    addresses
    high
    direct

    Telemetry modes ARE the configuration governing (2)(l)'s recording-and-monitoring channel; reducing it to beacons or replaying benign segments directly defeats the obligation.

  • DE-0003.08Received CommandsST0006
    addresses
    high
    direct

    Command histories and event logs ARE the (2)(l) recording channel; rewriting opcodes, timestamps, and source IDs is the canonical attack (2)(l) requires the product to resist.

  • DE-0003.09System Clock for EvasionST0006
    addresses
    moderate
    direct

    Reliable timestamps are foundational to (2)(l)'s recording-and-monitoring obligation; clock-bias evasion defeats reconstruction of sequences and causality during incident analysis.

  • DE-0003.11Watchdog Timer (WDT) for EvasionST0006
    addresses
    moderate
    direct

    WDT-induced resets that wipe volatile traces and break log correlation defeat the monitoring obligation (2)(l) places on the product.

  • Anomaly-detection / monitoring models ARE the (2)(l) recording-and-monitoring layer when the product implements ML-based security telemetry; clean-label backdoors and label flipping directly defeat the obligation.

  • DE-0007Evasion via RootkitST0006
    addresses
    moderate
    direct

    Rootkits invalidate the (2)(l) record-and-monitor obligation by tampering with reporting paths after boot; product design must consider tamper-resistant logging and out-of-band attestation.

  • DE-0010Overflow Audit LogST0006
    addresses
    high
    direct

    Exhausting ring buffers and recorder indexes so incriminating events overflow before downlink directly defeats (2)(l)'s record-and-monitor obligation; product design must provide reliable retention of security-relevant events.

  • DE-0011Credentialed EvasionST0006
    addresses
    high
    direct

    Detecting credentialed evasion requires recording and monitoring access to data, services, and functions — the (2)(l) obligation directly.

  • Manufacturer logging/monitoring obligation surfaces anomalous activations correlated with orbital state transitions, the observable signature of geofenced trigger logic.

  • EX-0008Time Synchronized ExecutionST0004
    addresses
    moderate
    derived

    Manufacturer logging/monitoring obligation surfaces anomalous activations keyed to time triggers; logging must capture time-correlation evidence that supports detection of dormant-trigger malicious logic.

  • EX-0008.01Absolute Time SequencesST0004
    addresses
    moderate
    derived

    Logging/monitoring obligation captures absolute-timestamp activations that are observable signatures of wall-clock-keyed triggers.

  • EX-0008.02Relative Time SequencesST0004
    addresses
    moderate
    derived

    Logging/monitoring obligation captures relative-time activations correlated with reset, safing or pattern-event references the trigger latches to.

  • EX-0010Malicious CodeST0004
    addresses
    moderate
    derived

    Logging and monitoring obligations require recording of relevant internal activity, including code-execution events that surface unauthorized executable logic.

  • EX-0010.03RootkitST0004
    addresses
    moderate
    derived

    Manufacturer logging/monitoring obligation requires recording of relevant internal activity — the visibility that surfaces inconsistencies between system-state reports and authoritative sources, the principal observable signature of rootkit presence.

  • EX-0012Modify On-Board ValuesST0004
    addresses
    moderate
    derived

    Logging/monitoring obligation captures parameter modifications and on-board-value changes as evidentiary trail.

  • EX-0012.12System ClockST0004
    addresses
    moderate
    derived

    Logging obligation requires reliable time references for forensic correlation; clock-tampering surfaces as anomaly in cross-source disagreement captured in logs.

  • EXF-0004Out-of-Band Communications LinkST0008
    addresses
    moderate
    direct

    Sparsely-supervised auxiliary paths defeat the recording-and-monitoring obligation by design; (2)(l) extends the obligation to all internal activity including secondary links.

  • EXF-0006Modify Communications ConfigurationST0008
    addresses
    moderate
    direct

    Covert auxiliary downlinks pointed at attacker-owned apertures evade mission monitoring; (2)(l)'s record-and-monitor obligation applies to RF emissions configuration as security-relevant internal activity.

  • EXF-0007Compromised Ground SystemST0008
    addresses
    moderate
    direct

    Bulk extraction blending with routine dissemination is detectable only through (2)(l)'s record-and-monitor obligation on file staging areas, distribution services, and cross-site links.

  • IA-0007Compromise Ground SystemST0003
    addresses
    high
    direct

    Manufacturer logging/monitoring obligation requires products to record relevant internal activity, including access to interfaces and configuration changes — the visibility that surfaces ground-system compromise.

  • IA-0007.02Malicious Commanding via Valid GSST0003
    addresses
    moderate
    derived

    Logging/monitoring obligation requires products to record commanding activity, surfacing anomalous command sequences from otherwise-legitimate operator workstations.

  • LM-0007Credentialed TraversalST0007
    addresses
    moderate
    direct

    Detecting credentialed traversal across approved interfaces requires the per-interface recording and monitoring obligation in (2)(l).

  • PER-0003Ground System PresenceST0005
    addresses
    high
    derived

    Logging and monitoring obligation requires products to record relevant internal activity; long-dwell attacker behaviour leaves observable signatures that the (2)(l) instrumentation surfaces.

  • PER-0005Credentialed PersistenceST0005
    addresses
    moderate
    direct

    Recording and monitoring access to data, services, or functions is the detection layer that catches credential misuse persisting over extended periods.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.