nis2-impl

Annex 11.2.1

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (17)

Techniques referencing this article

  • EXF-0010Payload Communication ChannelST0008
    addresses
    high
    derived

    Access-rights provisioning across the host–payload boundary is the operational lever that bounds whether payload code can read bus telemetry or host-bus data for embedding in payload products.

  • IA-0006Compromise Hosted PayloadST0003
    addresses
    high
    derived

    Access-rights provisioning between hosted payload and host bus is the operational lever that limits which payload commands the bus accepts and which bus telemetry the payload can read.

  • IA-0009Trusted RelationshipST0003
    addresses
    high
    derived

    Access-rights provisioning to third-party connections must follow the same provision-modify-remove discipline as internal accounts; trusted-relationship abuse is the consequence of stale or over-broad third-party rights.

  • Access-rights to data portals, shared repositories and federated identity systems must be provisioned, modified and removed under documented procedures that match collaborator role tenure.

  • IA-0009.03User SegmentST0003
    addresses
    moderate
    derived

    Access-rights to tasking portals, customer gateways and downstream processing pipelines must be provisioned and revoked under documented procedures; over-broad user-segment access is the enabler of this technique.

  • IMP-0006TheftST0009
    addresses
    moderate
    derived

    Access-rights provisioning bounds the population that can read or copy mission-critical datasets; over-broad access is the leverage data-theft attacks exploit.

  • LM-0001Hosted PayloadST0007
    addresses
    high
    derived

    Access-rights provisioning across the host–payload boundary is the operational lever that bounds which payload commands reach the bus and which bus telemetry the payload can read.

  • LM-0007Credentialed TraversalST0007
    addresses
    high
    derived

    Access-rights hygiene under the provision/modify/remove obligations bounds the scope of credentialed traversal; over-broad operator and service-account rights are the leverage this technique exploits.

  • PER-0003Ground System PresenceST0005
    addresses
    high
    derived

    Access-rights provisioning hygiene (revocation on role change, periodic review) is the operational lever that bounds the dwell time of persistent attacker access to ground systems.

  • PER-0005Credentialed PersistenceST0005
    addresses
    high
    derived

    Provision, modification and removal of access rights under documented procedures is the operational lever that prevents stale credentials from carrying persistent access across role changes, project transitions and offboarding.

  • RD-0002Compromise InfrastructureST0002
    addresses
    high
    derived

    Provision, modification and removal of access rights is the operational mechanism that bounds an attacker's footprint inside compromised infrastructure; stale or over-broad rights are the leverage the technique exploits.

  • RD-0002.01Mission-Operated Ground SystemST0002
    addresses
    moderate
    derived

    Access-rights provisioning hygiene at the mission-operated GS bounds the population the attacker can impersonate after foothold.

  • Provision, modification, removal and documentation of access rights to design repositories, ICD vaults, AIT records and contractor data rooms is the operational mechanism that prevents unauthorized retrieval of the engineering corpus the technique targets.

  • REC-0001.04Data BusST0001
    addresses
    moderate
    derived

    Access-rights provisioning to bus design repositories and AIT bus-test records is the operational mechanism that bounds who can extract bus topology information.

  • REC-0001.06Maneuver & ControlST0001
    addresses
    moderate
    derived

    Access-rights provisioning to GNC simulators, control-design repositories and Monte-Carlo dispersion artefacts bounds who can reconstruct GNC behaviour from internal sources.

  • REC-0001.08PowerST0001
    addresses
    moderate
    derived

    Access-rights provisioning to EPS modelling artefacts, fault-protection trees and autonomy thresholds bounds who can reconstruct power-related leverage points.

  • REC-0004.01Flight TerminationST0001
    addresses
    moderate
    derived

    Access-rights to FTS architecture documentation must be tightly bounded; provisioning, modification and removal of those rights is the operational lever that limits FTS-recon exposure.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.