nis2-impl

Annex 3.3.2

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (3)

Techniques referencing this article

  • EXF-0008Compromised Developer SiteST0008
    addresses
    moderate
    derived

    Contractors and integrators must be able to report suspicious events affecting their development environments back to the mission owner; Annex 3.3.2 requires that reporting mechanism to be communicated to suppliers, which is the upstream feeder for early dev-site compromise discovery.

  • EXF-0009Compromised Partner SiteST0008
    addresses
    moderate
    derived

    Partners must communicate breaches affecting shared infrastructure back to the entity; Annex 3.3.2 requires the entity to communicate event-reporting mechanisms to those suppliers/partners.

  • IA-0009.02VendorST0003
    addresses
    moderate
    derived

    Vendors with admin access must know how to report suspicious events back to the entity; Annex 3.3.2 requires the entity to communicate event-reporting mechanisms to suppliers.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.