Art. 92(2)
Mapped SPARTA techniques (6)
Techniques referencing this article
Art. 92(2)'s supply-chain-risk-strategy obligation is domain-relevant to colluding components, but the cited strategy mandate names no interdicting mechanism; component-provenance verification would be the interdiction.
92(2)'s strategy-to-reduce-risks-in-the-supply-chain (with Annex VII point 6 measures) directly targets the supply-chain insertion paths IA-0001 enumerates.
Adversaries renting commercial ground-station-as-a-service is mostly outside the operator's control, but 92(2)'s supply-chain risk-reduction strategy includes governance over the operator's own commercial-GSaaS providers — preventing adversary misuse of the operator's contracted ground assets.
92(2)'s strategy-to-reduce-risks-in-the-supply-chain obligation (with measures from Annex VII point 6) is directly aimed at the supply-chain attack surface that REC-0008 enumerates.
Art. 92(2)'s supply-chain risk-reduction strategy is domain-relevant to hardware-supplier reconnaissance, but names no mechanism interdicting the information-gathering.
Art. 92(2)'s supply-chain risk-reduction strategy is domain-relevant to software-factory reconnaissance, but names no mechanism interdicting the information-gathering.