nis2-impl

Annex 12.1.1

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (31)

Techniques referencing this article

  • DE-0003.12Poison AI/ML Training for EvasionST0006
    addresses
    moderate
    derived

    Training datasets and reference labels for security-monitoring models are mission-critical information assets whose classification level drives integrity and access controls.

  • DE-0008Evasion via BootkitST0006
    addresses
    moderate
    derived

    Boot-stage code and pre-OS images are top-classification assets whose classification governs the strict storage and integrity controls that prevent malicious modification.

  • EX-0004Compromise Boot MemoryST0004
    addresses
    moderate
    derived

    Boot ROM images and bootloader keys are top-classification assets; their classification governs the strict storage and access controls that prevent the pre-runtime manipulation this technique requires.

  • EX-0010.04BootkitST0004
    addresses
    moderate
    derived

    Boot images and pre-OS code are top-classification assets whose handling and integrity controls determine whether attacker modification is feasible at all.

  • EX-0012.06Science/Payload DataST0004
    addresses
    moderate
    derived

    Payload data, raw frames, Level-0 streams and metadata are mission-critical information assets whose classification level governs handling and integrity controls; in-place modification is precisely the leakage/integrity threat classification protects against.

  • EX-0012.13Poison AI/ML Training DataST0004
    addresses
    moderate
    derived

    Training datasets and reference labels are mission-critical information assets; their classification level drives the storage, access and integrity controls that constrain poisoning paths.

  • EXF-0003Signal InterceptionST0008
    addresses
    moderate
    derived

    Mission traffic in transit (payload products, housekeeping, command/ack exchanges) is classified information; the asset-classification obligation drives the encryption and link-protection decisions that resist interception offline reconstruction.

  • EXF-0003.01Uplink ExfiltrationST0008
    addresses
    moderate
    derived

    Uplink content (commands, table uploads, file transfers) is classified information assets; classification level drives the confidentiality controls that resist uplink interception.

  • EXF-0003.02Downlink ExfiltrationST0008
    addresses
    moderate
    derived

    Real-time telemetry, recorder playbacks and payload products are mission-critical information assets; the asset-classification obligation drives the encryption and link-protection decisions that determine whether downlink intercept yields decodable content.

  • EXF-0008Compromised Developer SiteST0008
    addresses
    moderate
    derived

    Development artefacts (source, test vectors, configuration data) are mission-critical information assets whose classification level governs storage and access controls.

  • IMP-0006TheftST0009
    addresses
    high
    derived

    Mission data is the principal target of theft attacks; the asset-classification obligation is the foundational control that drives the encryption, access and storage controls determining whether theft is feasible at all.

  • PER-0001Memory CompromiseST0005
    addresses
    moderate
    derived

    Boot ROMs and early-init configuration are top-classification assets; their classification governs the strict storage and access controls that prevent malicious modification at the source.

  • RD-0003.02Cryptographic KeysST0002
    addresses
    moderate
    derived

    Cryptographic key material is the highest-classification asset the entity holds; its classification and the controls that flow from it determine whether key acquisition is possible at all.

  • ICDs, block diagrams, SBOMs and AIT travelers are the precise category of mission-critical information assets that must receive a classification level under the asset-classification framework so that downstream handling and access controls can be calibrated to their sensitivity.

  • REC-0001.01Software DesignST0001
    addresses
    high
    derived

    Source code and stripped flight images are mission-critical information assets requiring classification so that storage, replication and sharing inherit the protection appropriate to crown-jewel software.

  • REC-0001.02FirmwareST0001
    addresses
    moderate
    derived

    Firmware images and bootloader configuration are mission-critical assets whose classification level drives the storage, transmission and sharing controls that determine whether reconnaissance can recover them at all.

  • REC-0001.03Cryptographic AlgorithmsST0001
    addresses
    high
    derived

    Cryptographic algorithm details, key types and key lifecycles are top-classification assets under any plausible asset-classification framework, which is the lever that drives strict need-to-know storage and handling.

  • REC-0001.04Data BusST0001
    addresses
    high
    derived

    Bus-protocol details (1553/SpaceWire timings, addressing, redundancy schemes) are mission-engineering assets; classifying them drives the handling and access-control controls that constrain bus reconnaissance.

  • REC-0001.05Thermal Control SystemST0001
    addresses
    moderate
    derived

    Thermal architecture envelopes, set-points and survival heater configuration are engineering-asset content whose classification governs storage and disclosure constraints.

  • REC-0001.06Maneuver & ControlST0001
    addresses
    high
    derived

    GNC algorithms, control gains and stability-margin documentation are mission-critical assets whose classification level drives strict storage and dissemination controls.

  • REC-0001.07PayloadST0001
    addresses
    high
    derived

    Payload command sets, operating modes and data-paths are sensitive mission assets whose classification drives the control regime that constrains payload-reconnaissance leakage.

  • REC-0001.08PowerST0001
    addresses
    moderate
    derived

    EPS topology, autonomy thresholds and battery configuration are engineering assets whose classification determines whether their exposure to recon is permitted by the asset framework.

  • REC-0001.09Fault ManagementST0001
    addresses
    moderate
    derived

    FDIR/safing logic and fault trees are crown-jewel mission assets; their classification level drives the strict need-to-know controls that prevent recon-driven prediction of the spacecraft's safe-mode behaviour.

  • Frequency plans, link-budget tables, modulation and FEC parameters are mission-critical communications assets; their classification level drives the storage and dissemination controls that determine the recon surface for an adversary's RF profile of the mission.

  • REC-0003.01Communications EquipmentST0001
    addresses
    moderate
    derived

    Comms-equipment topology and capability documents are mission-critical assets; their classification drives the controls that prevent extraction by a recon adversary.

  • REC-0003.02Commanding DetailsST0001
    addresses
    high
    derived

    TC framing, packet structures and authentication-field definitions are crown-jewel command-system assets whose classification determines who can reconstruct the commanding interface.

  • REC-0003.04Valid CredentialsST0001
    addresses
    moderate
    derived

    Credentials, tokens and key material are top-classification assets whose handling controls determine whether the recon adversary can ever harvest them in the first place.

  • REC-0004.01Flight TerminationST0001
    addresses
    moderate
    derived

    Flight-termination architecture, command-destruct authority and autonomous-flight-safety configuration are sensitive launch-segment assets; their classification level drives the controls that constrain FTS reconnaissance against the operator's launch-vehicle interface package.

  • REC-0005.02Downlink InterceptST0001
    addresses
    moderate
    derived

    Downlink content (housekeeping telemetry, payload products, event logs) is the asset whose classification determines whether downlink intercept exposes mission-critical information; the entity must classify this content so encryption and link-protection decisions are properly calibrated.

  • Source repositories, build artefacts and release manifests are classified information assets; the classification level is the input to the storage, transport and dissemination controls that constrain FSW-development reconnaissance.

  • REC-0006.02Security Testing ToolsST0001
    addresses
    moderate
    derived

    Test plans, fuzz-harness configurations and known-blind-spot inventories are highly sensitive assets; their classification governs the recon surface for an adversary mapping the entity's test-tool gaps.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.