nis2-impl

Annex 11.3.1

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (26)

Techniques referencing this article

  • DE-0001Disable Fault ManagementST0006
    addresses
    high
    derived

    Authority to alter FDIR thresholds, watchdog timeouts or safing autonomy is privileged-account authority; the privileged-account policy bounds the population and applies the review obligations that surface misuse.

  • Authority to disable telemetry channels, mute event reports or alter packet filter rates is privileged-account authority; the privileged-account policy bounds the population that can issue such modifications.

  • DE-0003On-Board Values ObfuscationST0006
    addresses
    moderate
    derived

    Authority to write to housekeeping registers and obfuscate operator-visible state is privileged-account authority; the privileged-account policy is the lever that bounds the population that can issue these obfuscations.

  • DE-0003.07Cryptographic ModesST0006
    addresses
    high
    derived

    Authority to switch crypto profiles, select keys or enter clear-mode is privileged-account authority; the privileged-account policy is the procedural lever that prevents single-actor downgrade-to-clear.

  • DE-0006Modify WhitelistST0006
    addresses
    moderate
    derived

    Authority to modify execution whitelists is privileged; the privileged-account policy applies its identification and review obligations to that population.

  • EX-0005.02Malicious Use of Hardware CommandsST0004
    addresses
    moderate
    derived

    Hardware-level commands (memory-mapped register writes, JTAG/test-mode commands) are privileged-account actions; the privileged-account policy bounds who can issue them and under what review.

  • EX-0006Disable/Bypass EncryptionST0004
    addresses
    moderate
    derived

    Operators authorized to alter encryption state are privileged-account holders; the privileged-account policy bounds the population, applies strong identification and requires review of crypto-disabling actions.

  • EX-0012Modify On-Board ValuesST0004
    addresses
    high
    derived

    Operators authorized to alter on-board values are privileged-account holders; the privileged-account policy bounds the population that can issue parameter modifications and applies strong identification and review obligations.

  • EX-0012.03Memory Write/LoadsST0004
    addresses
    high
    derived

    Memory-write authority is privileged; the privileged-account policy bounds who can issue raw memory operations and applies the review obligations that detect misuse.

  • EX-0012.07Propulsion SubsystemST0004
    addresses
    high
    derived

    Authority to alter propulsion parameters is privileged-account authority; the privileged-account policy bounds the population and applies strong identification.

  • ADCS-parameter modification authority is privileged; the privileged-account policy bounds the population and applies the review obligations that detect misuse.

  • EX-0012.09Electrical Power SubsystemST0004
    addresses
    moderate
    derived

    Authority to alter EPS parameters is privileged; the privileged-account policy applies its identification and review obligations to the population that holds it.

  • Authority to alter communications configuration is privileged-account authority; the privileged-account policy bounds the population that can issue such modifications and applies the review obligations that detect malicious reconfiguration.

  • EXF-0006.02TransponderST0008
    addresses
    moderate
    derived

    Authority to remap transponder paths and adjust translation parameters is privileged; the privileged-account policy bounds the population that can issue such mirroring/forwarding configurations.

  • EXF-0008Compromised Developer SiteST0008
    addresses
    moderate
    derived

    Build operators, simulator administrators and ATLO test controllers are privileged-account holders; the privileged-account policy bounds the population that can ever extract development artefacts at scale.

  • Operator commanding accounts are privileged accounts; the privileged-account policy specifies strong identification, separated administration and review obligations that constrain how a compromised mission-owned GS can issue mission-affecting commands.

  • IA-0009Trusted RelationshipST0003
    addresses
    moderate
    derived

    Where third parties hold privileged access (vendor admin, partner ops), the privileged-account policy bounds the population and applies the strong identification, separation and review obligations that limit trusted-relationship abuse.

  • IA-0009.02VendorST0003
    addresses
    high
    derived

    Vendor admin access is privileged-account access by definition; the privileged-account policy is the procedural lever that constrains how vendor accounts are provisioned, monitored and reviewed.

  • LM-0007Credentialed TraversalST0007
    addresses
    high
    derived

    Privileged-account policy bounds which credentials confer cross-boundary authority; the privileged-account discipline is the procedural lever that constrains how far credentialed traversal can travel.

  • PER-0004Replace Cryptographic KeysST0005
    addresses
    high
    derived

    Authority to replace cryptographic keys is privileged-account authority; the privileged-account policy bounds the population, applies strong identification and review obligations and resists single-actor key-rotation events.

  • PER-0005Credentialed PersistenceST0005
    addresses
    high
    derived

    Service accounts and maintenance accounts are privileged-account population; the privileged-account policy applies strong identification, periodic review and separation-of-duty requirements that detect attacker-controlled long-lived credentials.

  • RD-0003.02Cryptographic KeysST0002
    addresses
    moderate
    derived

    COMSEC custodians and key-management operators are privileged accounts under Annex 11.3; the privileged-account policy bounds the population that can ever extract live key material.

  • REC-0001.01Software DesignST0001
    addresses
    moderate
    direct

    Build operators, release engineers and code-signing custodians are privileged accounts under Annex 11.3, and the privileged-account policy is the procedural lever that bounds source-code and binary-with-symbol exposure to the smallest set of trusted operators.

  • REC-0001.03Cryptographic AlgorithmsST0001
    addresses
    moderate
    derived

    Custodians of cryptographic algorithm and key documentation are privileged-account holders by definition; the privileged-account policy bounds the population that can access COMSEC documentation.

  • Build pipelines, code-signing services and release-train operators are privileged-account environments whose access policies bound the population that can pull or copy FSW artefacts.

  • REC-0006.01Development EnvironmentST0001
    addresses
    moderate
    derived

    Privileged accounts on build servers, signing nodes and dev-cluster admin consoles are within the privileged-account population whose recon exposure must be constrained.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.