nis2-impl

Annex 3.2.1

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (52)

Techniques referencing this article

  • DE-0001Disable Fault ManagementST0006
    addresses
    high
    derived

    Monitoring-and-logging procedures must surface FDIR-disable events, watchdog-timeout extensions and limit-threshold widenings, which are the observable signatures of fault-management suppression.

  • DE-0002Disrupt or Deceive DownlinkST0006
    addresses
    high
    derived

    Monitoring-and-logging procedures must surface telemetry gaps and abnormal display-pipeline behaviour, which are the observable signatures of downlink disruption or deception.

  • DE-0002.01Inhibit Ground System FunctionalityST0006
    addresses
    moderate
    derived

    Monitoring-and-logging procedures must capture telemetry-processing pipeline anomalies, gaps and unexpected configuration changes that signal ground-system inhibition.

  • DE-0002.02Jam Link SignalST0006
    addresses
    moderate
    derived

    Monitoring-and-logging procedures must surface link-margin degradation and noise-floor excursions on the downlink, which are the observable signatures of jamming used as evasion.

  • Monitoring-and-logging procedures must surface telemetry-source quieting, packet-rate drops and event-channel muting, which are the observable signatures of source-side telemetry suppression.

  • DE-0003On-Board Values ObfuscationST0006
    addresses
    high
    derived

    Monitoring-and-logging must surface counter freezes, mode-flag inconsistencies and crypto-state divergences across redundant telemetry paths, which are the observable signatures of on-board-value obfuscation.

  • DE-0003.01Vehicle Command Counter (VCC)ST0006
    addresses
    high
    derived

    Monitoring procedures must capture VCC values, increment cadence and divergences from per-pass expected counts; this is the principal observable signature of VCC tampering.

  • DE-0003.02Rejected Command CounterST0006
    addresses
    moderate
    derived

    Monitoring procedures must capture rejected-command-counter drops, sudden zeroing and disagreement with command-history audit trails as observable signatures of evasion.

  • DE-0003.03Command Receiver On/Off ModeST0006
    addresses
    high
    derived

    Monitoring procedures must surface receiver-state changes that create deliberate quiet windows, which are observable from telemetry transitions and pass-coverage gaps.

  • Monitoring-and-logging procedures should capture AGC and lock-state telemetry trends to surface anomalous receiver behaviour configured to silently reject legitimate signals.

  • DE-0003.05Command Receiver Lock ModesST0006
    addresses
    high
    derived

    Monitoring-and-logging procedures must capture command-lock-state transitions, frame-lock anomalies and partial-acquisition telemetry, which are the observable signatures the adversary uses for geometry validation and quiet-window selection.

  • DE-0003.06Telemetry Downlink ModesST0006
    addresses
    moderate
    derived

    Monitoring-and-logging procedures should detect telemetry-mode transitions and per-VC/APID drop-outs that create selective evasion windows.

  • DE-0003.07Cryptographic ModesST0006
    addresses
    high
    derived

    Monitoring-and-logging procedures must surface crypto-state transitions (algorithm changes, key-set switches, encryption-off states) as high-severity logging events.

  • DE-0003.10GPS EphemerisST0006
    addresses
    moderate
    derived

    Monitoring procedures must surface PNT-solution anomalies (impossible jumps, cross-source disagreements with onboard ephemeris) that signal GPS-ephemeris spoofing.

  • DE-0003.11Watchdog Timer (WDT) for EvasionST0006
    addresses
    moderate
    derived

    Monitoring-and-logging procedures should capture WDT-configuration changes, reset-policy modifications and unusual reset cadences that signal evidence shaping.

  • Monitoring-and-logging must run continuously across mode transitions; safe-mode is precisely where reduced visibility creates the protection-subversion opportunity, and the implementing regulation does not exempt it.

  • DE-0007Evasion via RootkitST0006
    addresses
    high
    derived

    Monitoring-and-logging procedures must surface inconsistencies between system-state reports and authoritative sources (resource consumption, watchdog timing, redundant telemetry), which are the observable signatures rootkits attempt to hide.

  • Monitoring-and-logging procedures should surface SDA-feed anomalies, catalog-update inconsistencies and sensor-correlation drop-outs that signal SDA-pipeline compromise or spoofing.

  • DE-0011Credentialed EvasionST0006
    addresses
    high
    derived

    Monitoring-and-logging procedures must surface anomalous-but-credentialed activity (off-hours operator actions, geographic anomalies, command-pattern deviations) that signal evasion via valid credentials.

  • EX-0001ReplayST0004
    addresses
    moderate
    derived

    Monitoring-and-logging procedures must surface duplicate or out-of-sequence command/data events; replay attempts are observable in command counters and audit trails.

  • EX-0001.01Command PacketsST0004
    addresses
    moderate
    derived

    Command-side monitoring must detect duplicate frames and counter regressions, which are the observable signatures of command-packet replay.

  • Monitoring procedures must surface anomalous activation events keyed to orbital state; correlation between attitude/ephemeris transitions and unexpected behaviour is the observable signature of geofenced triggers.

  • EX-0006Disable/Bypass EncryptionST0004
    addresses
    moderate
    derived

    Monitoring-and-logging must surface encryption state changes; transitions to weaker or disabled crypto on TT&C or storage paths are observable and high-severity logging events.

  • EX-0008.01Absolute Time SequencesST0004
    addresses
    moderate
    derived

    Monitoring procedures should surface anomalous activations correlated with absolute timestamps and shared time-source events.

  • EX-0008.02Relative Time SequencesST0004
    addresses
    moderate
    derived

    Monitoring should correlate anomalous behaviour with prior reset/safing/comm-pattern events that match relative-time-trigger latch points.

  • EX-0010.03RootkitST0004
    addresses
    moderate
    derived

    Monitoring-and-logging procedures must surface anomalous system-state reporting and detect tampering with telemetry pipelines, which is the principal observable signature of rootkit presence.

  • Monitoring-and-logging procedures must run continuously across mode transitions; the implementing regulation does not exempt safe-mode windows from log retention and review.

  • EX-0012Modify On-Board ValuesST0004
    addresses
    high
    derived

    Monitoring-and-logging must surface parameter changes and anomalous on-board-value modifications; this is the detective control for unauthorized modification.

  • EX-0012.03Memory Write/LoadsST0004
    addresses
    moderate
    derived

    Monitoring-and-logging procedures must capture memory-write commands and post-effect telemetry, which are the observable signatures of malicious memory loading.

  • EX-0012.07Propulsion SubsystemST0004
    addresses
    moderate
    derived

    Monitoring-and-logging procedures must surface parameter modifications to safety-critical subsystems like propulsion before mission-affecting effects materialize.

  • EX-0012.11Watchdog Timer (WDT)ST0004
    addresses
    moderate
    derived

    Monitoring-and-logging procedures must capture WDT-configuration changes and reset-policy modifications, which are subtle observable signatures of liveness-supervision tampering.

  • EX-0013FloodingST0004
    addresses
    high
    derived

    Monitoring-and-logging procedures must surface anomalous traffic volume, command rates and parser-load events, which are the observable signatures of flooding attacks.

  • EX-0013.01Valid CommandsST0004
    addresses
    moderate
    derived

    Monitoring-and-logging procedures must surface elevated valid-command rates and unusual operator command-history patterns, which are the observable signatures of valid-command flooding.

  • EX-0014SpoofingST0004
    addresses
    moderate
    derived

    Monitoring-and-logging procedures must surface inputs that violate authenticator expectations, time/sequence consistency or sensor-fusion bounds — the observable signatures of spoofing.

  • Monitoring-and-logging procedures must surface PNT-solution anomalies (impossible jumps, cross-source disagreements) that signal spoofing.

  • EX-0016JammingST0004
    addresses
    moderate
    derived

    Monitoring-and-logging procedures must surface link-margin degradation and noise-floor excursions, which are the observable signatures of jamming.

  • EX-0016.01Uplink JammingST0004
    addresses
    moderate
    derived

    Monitoring procedures must capture uplink-margin reduction and acquisition failures, which are the observable signatures of uplink jamming.

  • EX-0016.02Downlink JammingST0004
    addresses
    moderate
    derived

    Monitoring procedures must surface degraded user-segment SNR, beam-blockage patterns and downlink-availability anomalies that signal jamming.

  • EXF-0001ReplayST0008
    addresses
    moderate
    derived

    Monitoring-and-logging procedures must surface duplicate or unauthorized-source command sequences that solicit recorder playbacks or bulk dumps, which is the observable signature of replay-driven exfiltration.

  • EXF-0004Out-of-Band Communications LinkST0008
    addresses
    moderate
    derived

    Monitoring-and-logging procedures must cover sparsely-supervised secondary links (beacons, rekeying paths, contingency profiles); the implementing regulation does not exempt low-rate housekeeping channels from log retention and review.

  • EXF-0006Modify Communications ConfigurationST0008
    addresses
    moderate
    derived

    Monitoring-and-logging procedures must surface link-configuration changes, anomalous sidebands and unexpected emissions toward non-mission receivers, which are the observable signatures of communications-config exfiltration.

  • EXF-0006.02TransponderST0008
    addresses
    moderate
    derived

    Monitoring procedures should surface transponder configuration changes and anomalous routing-table updates that signal transponder misuse for covert exfiltration.

  • EXF-0007Compromised Ground SystemST0008
    addresses
    high
    derived

    Monitoring-and-logging procedures must surface anomalous bulk-export activity, recorder-playback scraping and unusual cross-site link traffic, which are the observable signatures of compromised-ground-system exfiltration.

  • IA-0004Secondary/Backup Communication ChannelST0003
    addresses
    moderate
    derived

    Monitoring-and-logging procedures must cover backup paths because they are precisely the channels less frequently exercised and most likely to harbour unnoticed adversary presence.

  • IA-0004.01Ground StationST0003
    addresses
    high
    derived

    Monitoring-and-logging on standby MOC sites and reserve operator workstations must run continuously; the implementing regulation does not exempt seldom-used systems from log retention and review.

  • IA-0007Compromise Ground SystemST0003
    addresses
    high
    derived

    Monitoring-and-logging procedures on operator workstations, mission-control servers and gateway equipment are the detective control that surfaces a ground-system intrusion before commanding effects occur.

  • Monitoring-and-logging procedures must surface anomalous command sequences on otherwise legitimate operator workstations; this is the detective control for valid-GS-misuse.

  • IA-0010Unauthorized Access During Safe-ModeST0003
    addresses
    moderate
    derived

    Monitoring-and-logging procedures must run continuously, including during safe-mode windows; the implementing regulation does not exempt reduced-payload or contingency operating regimes from log retention and review.

  • IMP-0001Deception (or Misdirection)ST0009
    addresses
    high
    derived

    Monitoring-and-logging procedures must surface telemetry inconsistencies, cross-source disagreements and anomalous source patterns that signal deception or misdirection.

  • PER-0003Ground System PresenceST0005
    addresses
    high
    derived

    Monitoring-and-logging procedures are the principal detective control for ground-system persistence; long-dwell attacker behaviour leaves observable signatures across operator workstations, auth servers and gateway equipment.

  • RD-0002.01Mission-Operated Ground SystemST0002
    addresses
    moderate
    derived

    Monitoring-and-logging procedures are the detective control that surfaces a compromised mission-operated GS as adversary infrastructure before it is used for mission-impact actions.

  • REC-0005.04Active Scanning (RF/Optical)ST0001
    addresses
    moderate
    direct

    Active scanning is observable: the entity's monitoring-and-logging procedures must surface anomalous probe responses, frequency-sweep correlation and TT&C link-margin changes that signal an adversary scan.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.