nis2-impl

Annex 12.4.1

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (6)

Techniques referencing this article

  • EX-0009.03Known Vulnerability (COTS/FOSS)ST0004
    addresses
    moderate
    derived

    Asset-inventory obligations require maintenance of accurate, up-to-date software-component inventories; without them the entity cannot match known vulnerabilities to its installed COTS/FOSS surface.

  • IA-0001.03Hardware Supply ChainST0003
    addresses
    moderate
    derived

    Asset inventories at component granularity (lot, serial, configuration state) are the data on which lifecycle traceability and tamper-detection workflows depend; without that inventory the entity cannot reason about what was modified pre-delivery.

  • PER-0002.01Hardware BackdoorST0005
    addresses
    moderate
    derived

    Asset-inventory obligations at component granularity (lot, configuration, test history) underpin the lifecycle traceability needed to detect hardware-backdoor classes at delivery and during operations.

  • REC-0003.01Communications EquipmentST0001
    addresses
    high
    direct

    Inventories of communications equipment (antennas, transponders, modems, receivers) are exactly the asset-inventory content the implementing regulation requires the entity to maintain; the inventory's confidentiality classification determines whether equipment recon can succeed against the entity.

  • REC-0008.01Hardware ReconST0001
    addresses
    moderate
    derived

    Asset inventories at component granularity contain exactly the lot, serial and configuration data hardware reconnaissance targets; inventory protection determines whether that data is reachable.

  • REC-0008.02Software ReconST0001
    addresses
    moderate
    derived

    Software-asset inventories carry the version, dependency and provenance data the recon enumerates; their classification controls determine whether the data is exfiltrable through normal access paths.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.