cra

Annex I, Part II, (7)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (6)

Techniques referencing this article

  • EX-0004Compromise Boot MemoryST0004
    addresses
    moderate
    derived

    Secure update-distribution mechanisms protect boot-stage code paths; the same provenance and integrity requirements that protect runtime updates apply to boot-image updates.

  • EX-0010.04BootkitST0004
    addresses
    moderate
    derived

    Secure update-distribution mechanisms protect boot-stage code paths: the same provenance and integrity requirements that protect runtime updates apply to boot-image updates.

  • IA-0001.02Software Supply ChainST0003
    addresses
    high
    derived

    Manufacturer obligation to provide secure update-distribution mechanisms is the direct defense against altered/swapped binaries: signed, integrity-verified update channels resist signed-binary swap and update-metadata subversion.

  • IA-0007.01Compromise On-Orbit UpdateST0003
    addresses
    high
    derived

    Manufacturer obligation to provide secure update-distribution mechanisms is precisely the defense against on-orbit update pipeline manipulation: signed, integrity-verified update channels resist source-tree manipulation, build-step subversion and packaging tampering.

  • PER-0001Memory CompromiseST0005
    addresses
    moderate
    derived

    Secure update-distribution mechanisms protect modifications to memory regions whose integrity is critical (boot, FDIR, persistent configuration).

  • REC-0008.03Known VulnerabilitiesST0001
    addresses
    high
    derived

    Manufacturer obligation to provide secure update-distribution mechanisms ensures that remediation actually reaches deployed products; without that distribution path, vulnerability-handling discipline upstream cannot close the exploit window the adversary's recon attempts to widen.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.