Art. 76(5)
Mapped SPARTA techniques (12)
Techniques referencing this article
Bootkit risk (primary: Art. 76(4) manufacturing/test phases) requires ISMS-level lifecycle treatment under 76(5).
Code-flaw exploitation (primary mappings: Art. 76(2) resilience + Art. 78(1) vulnerability identification) cascades to 76(5) — the ISMS is the management discipline that maintains vulnerability registers and risk treatment over the support period.
FSW vulnerability identification (primary mapping: Art. 78(1)) is part of the overall ISMS 76(5) requires; vulnerability registers are an ISMS artifact.
OS-layer vulnerabilities (primary: Art. 78(1)) need ISMS-level tracking and risk treatment per 76(5).
Known-vulnerability exposure (primary: Art. 78(1)) is the canonical ISMS-managed risk; CPE/CVE registers and treatment plans live in the ISMS per 76(5).
Compromised-developer-site exfiltration (primary: Art. 76(4) lifecycle) requires ISMS coverage of the development phase per 76(5)'s integrate-all-sources-of-risk obligation.
Supply-chain compromise (primary: Art. 76(4) lifecycle + Art. 92(1) supply chain) is an ISMS-managed risk class; 76(5) is the management framework that integrates supply-chain risk into overall risk treatment.
Rendezvous & proximity operations (primary: Art. 76(2) resilience) are an ISMS-managed risk scenario for proximity-aware missions per 76(5).
Safe-mode unauthorized-access risk (primary: Art. 76(2) resilience) is part of the ISMS-managed contingency-mode risk register per 76(5).
ATLO-stage compromise (primary: Art. 76(4) manufacturing/test phases) is an ISMS-managed lifecycle risk per 76(5).
Backdoor identification and treatment (primary: Art. 78(1)) belongs in the ISMS register as a high-severity operator-side risk per 76(5).
Known-vulnerability reconnaissance (primary: Art. 78(1)) directly engages ISMS vulnerability-register discipline; 76(5)'s ISMS is the management container for the operator's vulnerability landscape.