nis2-impl

Annex 11.7.1

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (15)

Techniques referencing this article

  • DE-0002.01Inhibit Ground System FunctionalityST0006
    addresses
    moderate
    derived

    Multi-factor authentication on telemetry-processing servers and operator displays prevents credential-only foothold from converting into the configuration changes that suppress ground-system telemetry rendering.

  • Multi-factor authentication on commanding paths must remain enforced during safe-mode; relaxation of MFA in contingency operations creates exactly the protection-subversion window this technique exploits.

  • DE-0011Credentialed EvasionST0006
    addresses
    high
    derived

    Multi-factor authentication ensures that even valid credentials require an additional factor; passive credential reuse for evasion is broken by MFA enforcement on commanding paths.

  • Multi-factor authentication on commanding paths must remain enforced during safe-mode operations; contingency commanding does not justify a relaxed authentication regime under the implementing regulation.

  • EXF-0007Compromised Ground SystemST0008
    addresses
    high
    derived

    Multi-factor authentication on operator workstations, archive databases and distribution services is the procedural defense that prevents credential-only foothold from converting into bulk-exfiltration access.

  • IA-0004.01Ground StationST0003
    addresses
    high
    derived

    Multi-factor authentication is required on commanding paths; backup-ground-station operator stations and contingency commercial-station gateways must enforce MFA at the same strength as the primary site.

  • IA-0007Compromise Ground SystemST0003
    addresses
    high
    derived

    Multi-factor authentication on operator workstations and TT&C automation is required by the implementing regulation; it is the procedural defense that prevents a credential foothold from converting into live commanding access.

  • Multi-factor authentication on commanding consoles is the procedural lever that prevents valid GS infrastructure (already configured for the mission) from being driven by a compromised credential alone.

  • IA-0009.02VendorST0003
    addresses
    high
    derived

    Multi-factor authentication on vendor remote-administration paths is the procedural defense that prevents a vendor credential leak from converting into operations-affecting access.

  • IA-0010Unauthorized Access During Safe-ModeST0003
    addresses
    moderate
    derived

    Multi-factor authentication on commanding paths must remain enforced during safe-mode operations; emergency commanding does not justify a relaxed authentication regime under the implementing regulation.

  • LM-0007Credentialed TraversalST0007
    addresses
    high
    derived

    Multi-factor authentication on commanding and administrative paths breaks the convertibility of passively reused credentials into cross-boundary traversal.

  • PER-0003Ground System PresenceST0005
    addresses
    high
    derived

    Multi-factor authentication on operator workstations and TT&C automation breaks the conversion from persistent foothold to live commanding access, even where the attacker has achieved long-lived credential capture.

  • PER-0005Credentialed PersistenceST0005
    addresses
    high
    derived

    Multi-factor authentication on accounts that confer commanding access prevents harvested or replayed credentials from yielding live persistence — even a long-lived password is insufficient on its own.

  • Multi-factor authentication on operator workstations and TT&C automation is the authentication procedure that prevents harvested or replayed credentials from converting into live commanding access.

  • REC-0003.04Valid CredentialsST0001
    addresses
    high
    direct

    Multi-factor authentication is the procedural and technical defense that converts credential-reconnaissance success into a still-blocked authentication attempt.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.