Annex 3.3.2
Mapped SPARTA techniques (3)
Techniques referencing this article
Contractors and integrators must be able to report suspicious events affecting their development environments back to the mission owner; Annex 3.3.2 requires that reporting mechanism to be communicated to suppliers, which is the upstream feeder for early dev-site compromise discovery.
Partners must communicate breaches affecting shared infrastructure back to the entity; Annex 3.3.2 requires the entity to communicate event-reporting mechanisms to those suppliers/partners.
Vendors with admin access must know how to report suspicious events back to the entity; Annex 3.3.2 requires the entity to communicate event-reporting mechanisms to suppliers.