cra

Annex I, Part II, (3)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (33)

Techniques referencing this article

  • DE-0005Subvert Protections via Safe-ModeST0006
    addresses
    moderate
    direct

    Subvert-protections-via-safe-mode (primary mapping: Annex I, Part I, (2)(k) exploitation mitigation) requires regular tests under (3) of the safe-mode posture itself — only repeated security review validates that contingency dictionaries do not relax authentication beyond intended.

  • DE-0006Modify WhitelistST0006
    addresses
    moderate
    direct

    Modify-whitelist (primary mapping: Annex I, Part I, (2)(k)) requires regular tests under (3) of whitelist tamper-resistance — periodic verification that the whitelist enforcement mechanism remains intact.

  • DE-0007Evasion via RootkitST0006
    addresses
    high
    direct

    Rootkit evasion (primary mapping: Annex I, Part I, (2)(k)) cascades to (3)'s regular-tests obligation — exploitation-mitigation mechanisms (signed code, control-flow integrity) require ongoing validation through fuzzing and integrity-attestation tests.

  • DE-0008Evasion via BootkitST0006
    addresses
    high
    direct

    Bootkit evasion (primary mapping: Annex I, Part I, (2)(k)) cascades to (3) — secure-boot and root-of-trust mitigations require regular boot-chain integrity testing to validate that bootkit attacks remain detected.

  • Onboard SSA/SDA-sensor deception (primary mapping: Annex I, Part I, (2)(k)) requires regular tests under (3) of the fusion algorithm's robustness against adversarial inputs (dazzling, spoofed transponder replies).

  • Ground-SDA corruption/overload (primary mapping: Annex I, Part I, (2)(k)) requires regular tests under (3) of the ingestion and detection-model robustness against adversarial inputs.

  • Effective and regular tests and reviews of product security surface dormant geofenced trigger logic before release; static analysis, taint analysis and behavior-state testing are within the scope of (3).

  • EX-0008Time Synchronized ExecutionST0004
    addresses
    moderate
    derived

    Effective and regular security tests and reviews surface time-keyed dormant logic before release; behavior-state and time-fast-forward testing fall within (3) scope.

  • EX-0008.01Absolute Time SequencesST0004
    addresses
    moderate
    derived

    Regular security testing is the manufacturer-side discipline that uncovers absolute-time dormant-trigger code in the product before release.

  • EX-0008.02Relative Time SequencesST0004
    addresses
    moderate
    derived

    Effective security testing surfaces relative-time-keyed triggers that activate after specific event sequences.

  • EX-0009Exploit Code FlawsST0004
    addresses
    high
    derived

    Effective and regular security testing (static analysis, fuzzing, integration testing) surfaces code flaws before they reach production, narrowing the attack surface.

  • EX-0009.01Flight SoftwareST0004
    addresses
    high
    derived

    Effective and regular tests and reviews (static analysis, fuzzing of command parsers and table loaders, integration testing on flatsats) are the manufacturer-side discipline that surfaces FSW flaws before flight.

  • EX-0010Malicious CodeST0004
    addresses
    moderate
    direct

    Malicious-code-execution exploitation (primary mapping: Annex I, Part I, (2)(k)) cascades to (3)'s regular-tests obligation — exploitation-mitigation mechanisms must be validated through ongoing security testing.

  • EX-0010.02Wiper MalwareST0004
    addresses
    moderate
    direct

    Memory-tampering exploitation (primary mapping: Annex I, Part I, (2)(k)) requires regular tests under (3) — memory-protection mitigations need periodic validation through fuzzing and overflow testing.

  • EX-0012.13Poison AI/ML Training DataST0004
    addresses
    moderate
    derived

    Effective and regular tests and reviews extend to model validation (data-distribution checks, robustness testing) that surfaces poisoning effects before deployment.

  • EX-0013.02Erroneous InputST0004
    addresses
    moderate
    derived

    Security testing (fuzzing of telecommand parsers and bus decoders) is the manufacturer-side discipline that surfaces parser fragility erroneous-input flooding exploits.

  • EX-0014.03Sensor DataST0004
    addresses
    moderate
    derived

    Security testing of estimation pipelines and outlier-rejection logic surfaces fragility that fabricated sensor data exploits.

  • EX-0015Side-Channel AttackST0004
    addresses
    moderate
    derived

    Effective and regular tests and reviews include side-channel-resistance testing (DPA/SPA, EM probing, timing analysis) as part of the manufacturer's security-testing program.

  • EXF-0002Side-Channel ExfiltrationST0008
    addresses
    moderate
    direct

    Side-channel exfiltration parent (primary mapping: Annex I, Part I, (2)(k)) cascades to (3) — side-channel countermeasures (masking, blinded crypto, EM shielding) require regular validation through dedicated side-channel testing.

  • EXF-0002.01Power Analysis AttacksST0008
    addresses
    moderate
    direct

    Power-analysis attacks (primary mapping: Annex I, Part I, (2)(k)) require regular DPA/CPA testing under (3) — masking and randomization countermeasures lose effectiveness if not validated under realistic measurement scenarios.

  • EXF-0002.02Electromagnetic Leakage AttacksST0008
    addresses
    moderate
    direct

    Electromagnetic-leakage attacks (primary mapping: Annex I, Part I, (2)(k)) cascade to (3) — TEMPEST shielding requires regular validation by near-field probe testing in the security review.

  • EXF-0002.04Timing AttacksST0008
    addresses
    high
    direct

    Timing attacks (primary mapping: Annex I, Part I, (2)(k)) require regular constant-time-implementation testing under (3) — micro-architectural changes can reintroduce timing variance over the support period.

  • EXF-0002.05Thermal Imaging attacksST0008
    addresses
    moderate
    direct

    Thermal-imaging attacks (primary mapping: Annex I, Part I, (2)(k)) cascade to (3) — thermal-balancing countermeasures require periodic validation through thermal-imaging-based security testing.

  • EXF-0005Proximity OperationsST0008
    addresses
    moderate
    direct

    Proximity-operations TEMPEST/EMSEC exfiltration (primary mapping: Annex I, Part I, (2)(k)) requires regular EMSEC validation under (3) — proximity attack vectors evolve with sensor capabilities, demanding ongoing testing.

  • EXF-0008Compromised Developer SiteST0008
    addresses
    high
    direct

    Effective and regular security tests must extend to test harnesses, simulators, and flight builds — the development-pipeline artifacts EXF-0008 attacks; (Part II, 3)'s testing obligation applies to the supply chain that produces the product.

  • IA-0006Compromise Hosted PayloadST0003
    addresses
    moderate
    direct

    Regular security tests and reviews of the product would exercise the hosted payload's exposed command sets, file services, and payload-host bus interface, surfacing the rarely-used modes, table-load and firmware-update paths, and unvalidated command channels that this technique exploits for a first foothold. Without that recurring testing discipline, the cross-strapped and contingency-mode behaviors that appear only in maintenance go unprobed and remain available to an attacker who knows the interface specification.

  • IA-0007Compromise Ground SystemST0003
    addresses
    moderate
    direct

    Secondary/backup-comm initial-access (primary mapping: Annex I, Part I, (2)(k)) requires regular testing under (3) of the alternate-channel security posture — these channels often miss the test scope of primary TT&C.

  • IA-0013Compromise Host SpacecraftST0003
    addresses
    moderate
    direct

    IA-0013 gains initial access by exploiting vulnerabilities in the host spacecraft's onboard systems, communication interfaces, and software, which are exactly the weaknesses that the obligation to apply effective and regular tests and reviews of the product's security is meant to surface. Regular security testing of the host vehicle reduces the unaddressed onboard flaws an adversary uses to reach the hosted payload, supporting an addresses-level relationship.

  • IMP-0004DegradationST0009
    addresses
    moderate
    direct

    Degradation-impact (primary mapping: Annex I, Part I, (2)(k)) cascades to (3) — exploitation-mitigation mechanisms (rate limiting, watchdog-bounded operation) require regular tests to validate effectiveness against degradation scenarios.

  • LM-0005Virtualization EscapeST0007
    addresses
    moderate
    direct

    Effective and regular tests of separation-kernel/hypervisor boundaries (fuzzing of message ports, IOMMU validation) is the (Part II, 3) obligation manufacturers must apply for products relying on virtualization separation.

  • PER-0002BackdoorST0005
    addresses
    high
    derived

    Effective and regular security testing (static analysis, taint analysis, behavioural testing of authentication paths) is the procedural mechanism that surfaces backdoors before they reach production.

  • PER-0002.02Software BackdoorST0005
    addresses
    high
    derived

    Security-testing procedures (taint analysis, integration-level authentication tests) surface software backdoors before they reach production.

  • REC-0006.02Security Testing ToolsST0001
    addresses
    moderate
    direct

    Annex I, Part II, (3) requires manufacturers to apply effective and regular tests and reviews of product security; the same disciplined testing program that surfaces vulnerabilities also drives the test-tool inventory that security-testing-tools reconnaissance attempts to enumerate, but a manufacturer that systematically tests narrows the gap-discovery surface.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.