Annex I, Part I, (2)(l)
Mapped SPARTA techniques (30)
Techniques referencing this article
FDIR alerts and event routing ARE the security-related information channel; suppressing them is the precise failure (2)(l) requires recording and monitoring of internal activity to prevent.
(2)(l) requires recording and monitoring of internal activity, including modification of services or functions — the telemetry-publisher reconfiguration that (2)(l) is meant to surface as security-related information.
The values being obfuscated (counters, flags, mode indicators) are the very recording fields (2)(l) requires the product to maintain for security-relevant internal activity monitoring.
The VCC is a primary recording channel for command-acceptance activity; (2)(l)'s record-and-monitor requirement is precisely defeated when the counter is biased or hidden.
Rejection counts and reason codes are core security-monitoring telemetry — exactly the recording fields (2)(l) requires for surfacing failed-authentication and probe activity.
Lock-status indicators and counters are recording fields whose tampering defeats (2)(l)'s monitoring obligation.
Telemetry modes ARE the configuration governing (2)(l)'s recording-and-monitoring channel; reducing it to beacons or replaying benign segments directly defeats the obligation.
Command histories and event logs ARE the (2)(l) recording channel; rewriting opcodes, timestamps, and source IDs is the canonical attack (2)(l) requires the product to resist.
Reliable timestamps are foundational to (2)(l)'s recording-and-monitoring obligation; clock-bias evasion defeats reconstruction of sequences and causality during incident analysis.
WDT-induced resets that wipe volatile traces and break log correlation defeat the monitoring obligation (2)(l) places on the product.
Anomaly-detection / monitoring models ARE the (2)(l) recording-and-monitoring layer when the product implements ML-based security telemetry; clean-label backdoors and label flipping directly defeat the obligation.
Rootkits invalidate the (2)(l) record-and-monitor obligation by tampering with reporting paths after boot; product design must consider tamper-resistant logging and out-of-band attestation.
Exhausting ring buffers and recorder indexes so incriminating events overflow before downlink directly defeats (2)(l)'s record-and-monitor obligation; product design must provide reliable retention of security-relevant events.
Detecting credentialed evasion requires recording and monitoring access to data, services, and functions — the (2)(l) obligation directly.
Manufacturer logging/monitoring obligation surfaces anomalous activations correlated with orbital state transitions, the observable signature of geofenced trigger logic.
Manufacturer logging/monitoring obligation surfaces anomalous activations keyed to time triggers; logging must capture time-correlation evidence that supports detection of dormant-trigger malicious logic.
Logging/monitoring obligation captures absolute-timestamp activations that are observable signatures of wall-clock-keyed triggers.
Logging/monitoring obligation captures relative-time activations correlated with reset, safing or pattern-event references the trigger latches to.
Logging and monitoring obligations require recording of relevant internal activity, including code-execution events that surface unauthorized executable logic.
Manufacturer logging/monitoring obligation requires recording of relevant internal activity — the visibility that surfaces inconsistencies between system-state reports and authoritative sources, the principal observable signature of rootkit presence.
Logging/monitoring obligation captures parameter modifications and on-board-value changes as evidentiary trail.
Logging obligation requires reliable time references for forensic correlation; clock-tampering surfaces as anomaly in cross-source disagreement captured in logs.
Sparsely-supervised auxiliary paths defeat the recording-and-monitoring obligation by design; (2)(l) extends the obligation to all internal activity including secondary links.
Covert auxiliary downlinks pointed at attacker-owned apertures evade mission monitoring; (2)(l)'s record-and-monitor obligation applies to RF emissions configuration as security-relevant internal activity.
Bulk extraction blending with routine dissemination is detectable only through (2)(l)'s record-and-monitor obligation on file staging areas, distribution services, and cross-site links.
Manufacturer logging/monitoring obligation requires products to record relevant internal activity, including access to interfaces and configuration changes — the visibility that surfaces ground-system compromise.
Logging/monitoring obligation requires products to record commanding activity, surfacing anomalous command sequences from otherwise-legitimate operator workstations.
Detecting credentialed traversal across approved interfaces requires the per-interface recording and monitoring obligation in (2)(l).
Logging and monitoring obligation requires products to record relevant internal activity; long-dwell attacker behaviour leaves observable signatures that the (2)(l) instrumentation surfaces.
Recording and monitoring access to data, services, or functions is the detection layer that catches credential misuse persisting over extended periods.