Annex I, Part II, (8)
Mapped SPARTA techniques (15)
Techniques referencing this article
Flight-software exploitation handled through the secure-update channel (primary mapping: Part II, (7)) cascades to (8)'s timely-dissemination obligation — secure update distribution and dissemination-without-delay are paired.
Hardware supply-chain backdoor exploitation (primary mapping: Part II, (2)) cascades to (8) — once a remediating update exists, the manufacturer must disseminate it without delay.
Vulnerability exploitation parent (primary mapping: Part II, (2) remediate) cascades to (8) — the timing element of remediation is dissemination without delay.
Known-vulnerability exploitation (primary mapping: Part II, (2) remediate) cascades to (8) — the patch must reach affected products without delay once available.
Zero-day exploitation (primary mapping: Part II, (2) remediate) cascades to (8) — once a fix is developed for an undisclosed vulnerability, dissemination without delay is the operational obligation.
Manufacturer obligation to disseminate security updates without delay closes the exploit window once remediation is available.
Stack/heap-memory exploitation handled via secure update distribution (primary mapping: Part II, (7)) cascades to (8) — the secure-distribution and timely-dissemination obligations work in tandem.
SDR-modification exfiltration (primary mapping: Part I, (2)(c) security updates) cascades to (8) — when the attack rides 'legitimate updates', the manufacturer's update channel must include the timely-dissemination discipline that legitimate fixes require.
Software-dependency compromise (primary mapping: Part II, (2)) cascades to (8) — once a remediating update is available, dissemination without delay is the timing element.
Software supply-chain compromise (primary mapping: Part II, (7)) cascades to (8) — secure update distribution is paired with the timely-dissemination obligation.
Compromised-software-update initial-access (primary mapping: Part I, (2)(c) security updates) cascades to (8) — the (2)(c) obligation includes dissemination without delay as the timing element.
Malicious commands during firmware update (primary mappings: Part I, (2)(c) + Part II, (7)) cascade to (8) — once corrective updates exist, timely dissemination is the operational obligation.
Malicious-update persistence (primary mapping: Part II, (7)) cascades to (8) — the legitimate update channel that countervails malicious-update persistence must maintain timely dissemination of remediating fixes.
Eavesdropping on update channels (primary mapping: Part I, (2)(c)) cascades to (8) — the security-update obligation in (2)(c) includes the dissemination-without-delay timing element under (8).
Manufacturer obligation to disseminate security updates without delay once available is the temporal discipline that bounds the exploit window for known vulnerabilities.