nis2-impl

Annex 5.1.1

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (42)

Techniques referencing this article

  • DE-0003.12Poison AI/ML Training for EvasionST0006
    addresses
    moderate
    derived

    Anomaly-detection model training data is supplied through data brokers, telemetry-archive providers and ML-as-a-service vendors; the supply-chain policy governs how these data suppliers are vetted, contracted and monitored.

  • External SDA providers (commercial and government) are direct suppliers under the supply-chain policy; the policy governs how the entity vets, contracts with and monitors the data flows from those tracking centers.

  • DE-0012Component CollusionST0006
    addresses
    high
    derived

    Coordinated compromise of multiple software modules during the supply chain process is the canonical multi-supplier collusion threat the supply-chain policy is established to govern.

  • Hardware/firmware corruption rides through the supplier relationship that produces the affected component; the supply-chain policy is the procedural mechanism that scopes the verification regime applied at delivery.

  • EX-0005.01Design FlawsST0004
    addresses
    high
    derived

    Design flaws and errata enter through the supplier of the affected silicon, board or programmable logic; the supply-chain policy frames the security expectations on supplier-disclosed errata and supplier-conducted design review.

  • EX-0009.03Known Vulnerability (COTS/FOSS)ST0004
    addresses
    moderate
    derived

    COTS/FOSS suppliers (foundations, vendors) are direct suppliers under the supply-chain policy; their disclosure and security-quality posture shape the known-vulnerability surface the entity inherits.

  • EX-0012.13Poison AI/ML Training DataST0004
    addresses
    high
    derived

    AI/ML training data is supplied through data brokers, annotation services and pretrained-model vendors; the supply-chain policy is the procedural mechanism that constrains how those data suppliers are vetted and monitored.

  • EXF-0006.01Software Defined RadioST0008
    addresses
    moderate
    derived

    SDR vendors and waveform suppliers are direct suppliers under the supply-chain policy; the policy frames the integrity expectations on vendor-supplied DSP chains and configuration profiles that, if subverted, deliver covert downlinks.

  • EXF-0008Compromised Developer SiteST0008
    addresses
    high
    derived

    Contractor and integrator development environments are direct suppliers under the supply-chain policy; the policy frames the security expectations imposed on those environments where pre-launch exfiltration occurs.

  • EXF-0009Compromised Partner SiteST0008
    addresses
    high
    derived

    Commercial ground stations, relay networks, operations service providers and data-processing partners are direct suppliers under the supply-chain policy; the policy governs the security expectations imposed on these partner environments where multi-mission exfiltration originates.

  • EXF-0010Payload Communication ChannelST0008
    addresses
    moderate
    derived

    Payload vendors, gateway operators and customer-network providers are direct suppliers under the supply-chain policy; the policy frames the integrity expectations imposed on the payload-communications channel and its endpoints.

  • IA-0001Compromise Supply ChainST0003
    addresses
    high
    direct

    Compromise Supply Chain is exactly the threat the supply-chain security policy is established to govern; the policy defines who the entity contracts with, the security obligations imposed on those suppliers, and the verification and audit regime applied to each tier of the parts and software pipeline.

  • Open-source maintainers, package registries and CI/CD service providers are direct suppliers under the supply-chain policy; the policy's selection and monitoring obligations apply to them as much as to silicon vendors.

  • IA-0001.02Software Supply ChainST0003
    addresses
    high
    derived

    Software delivered to flight or ground systems traverses the supplier network the supply-chain security policy governs; that policy is the procedural envelope around vendor identity, provenance and integrity.

  • IA-0001.03Hardware Supply ChainST0003
    addresses
    high
    derived

    ASIC/FPGA Trojans, modified bootloaders and pre-delivery board manipulation are the canonical hardware-supply-chain threats the supply-chain security policy is established to govern.

  • SDR vendors and waveform suppliers are direct suppliers governed by the supply-chain policy; that policy frames the integrity expectations on vendor-supplied bitstreams, flowgraphs and configuration profiles.

  • IA-0003Crosslink via Compromised NeighborST0003
    addresses
    moderate
    derived

    Constellation partners and shared-routing collaborators are suppliers under the supply-chain policy when they exchange routes, time discipline or relay services with the entity's vehicle.

  • IA-0004.01Ground StationST0003
    addresses
    moderate
    derived

    Alternate commercial ground stations held in reserve are direct suppliers under the supply-chain policy; the policy's verification and contractual obligations apply to them irrespective of their reserve status.

  • IA-0005Rendezvous & Proximity OperationsST0003
    addresses
    moderate
    derived

    Operators of vehicles that conduct close-proximity operations near the entity's spacecraft are functional suppliers when their proximity is contractually arranged (rideshare, OSAM, cooperative sensing); the supply-chain policy governs how the entity vets such counterparties.

  • IA-0005.02Docked Vehicle / OSAMST0003
    addresses
    high
    derived

    OSAM servicers, cargo vehicles and visiting vehicles are functional suppliers of services delivered through a docking/berthing interface; the supply-chain policy governs how the entity contracts for and verifies the security posture of these counterparties.

  • IA-0006Compromise Hosted PayloadST0003
    addresses
    moderate
    derived

    The hosted-payload provider is a direct supplier under the supply-chain policy; the policy frames the integration security expectations imposed on payload code, file services and telemetry paths.

  • IA-0009Trusted RelationshipST0003
    addresses
    high
    derived

    Trusted relationships, with partners, vendors and user communities, are exactly the relationships the supply-chain policy is established to govern; the policy specifies how the entity contracts with and monitors third parties whose connections it trusts.

  • Mission collaborators (universities, science operations centers, international partners) are direct suppliers under the supply-chain policy; the policy governs the security expectations and shared-credential discipline imposed on those collaborators.

  • IA-0009.02VendorST0003
    addresses
    high
    derived

    Vendors with persistent administrative routes into mission systems (ground software, modems, identity providers) are the canonical direct-supplier population the supply-chain policy governs.

  • IA-0009.03User SegmentST0003
    addresses
    high
    derived

    User-segment equipment suppliers, downstream processing partners and customer-gateway providers are direct suppliers under the supply-chain policy; the policy frames the security expectations imposed on the user-facing edge of the mission's distribution network.

  • IA-0011Auxiliary Device CompromiseST0003
    addresses
    moderate
    derived

    Auxiliary-device suppliers (EGSE vendors, calibration tooling, external storage providers) are direct suppliers under the supply-chain policy, which governs the trust expectations imposed on the devices that ingest into spacecraft and support equipment.

  • AIT facilities, integrators and pad-side service providers are direct suppliers under the supply-chain policy; that policy governs the security regime imposed at AIT and during launch operations.

  • IA-0013Compromise Host SpacecraftST0003
    addresses
    high
    derived

    Where the entity's payload is hosted on a third-party spacecraft, the host operator is a direct supplier under the supply-chain policy; the policy governs the integration-security expectations imposed on the host bus.

  • LM-0004Visiting Vehicle Interface(s)ST0007
    addresses
    high
    derived

    Visiting-vehicle operators (cargo, OSAM, crewed) are functional suppliers when their vehicles dock or berth; the supply-chain policy governs the security expectations imposed on these counterparties.

  • LM-0006Launch Vehicle InterfaceST0007
    addresses
    high
    derived

    Launch-vehicle providers, integrators and EGSE network operators are direct suppliers under the supply-chain policy; the policy frames the security expectations imposed on the integration-period interface.

  • LM-0006.01Rideshare PayloadST0007
    addresses
    high
    derived

    Rideshare cohabitants and deployer operators are direct suppliers under the supply-chain policy; the policy governs the security expectations imposed on shared infrastructure across rideshare manifest entries.

  • PER-0002.01Hardware BackdoorST0005
    addresses
    high
    derived

    Hardware backdoors enter through suppliers (test/scan-chain enablement, undocumented bootstrap modes, microarchitectural quirks); the supply-chain policy is the procedural mechanism that scopes the verification regime applied at delivery.

  • PER-0002.02Software BackdoorST0005
    addresses
    moderate
    derived

    Software supply chains are the principal vehicle for backdoor introduction; the supply-chain policy frames the security expectations on supplier secure-development practices that bound this risk.

  • When the entity itself rents commercial ground-station services, the supply-chain security policy is the procedural framework that constrains how the entity vets, contracts with and audits its GSaaS provider, the same provider an adversary can rent into.

  • RD-0002.023rd Party Ground SystemST0002
    addresses
    high
    derived

    Third-party ground systems are direct suppliers under the supply-chain security policy; the policy is the procedural mechanism that constrains the security posture the entity accepts from its GSaaS or relay provider.

  • RD-0002.033rd-Party SpacecraftST0002
    addresses
    moderate
    derived

    Compromise of a third-party operator's spacecraft acting as proxy or relay engages the entity's supply-chain policy when the entity uses that operator's services or shares a bus/payload; the policy bounds what the entity accepts from the host operator.

  • REC-0001.02FirmwareST0001
    addresses
    high
    direct

    Firmware reconnaissance leans heavily on vendor reference packages and leaked manufacturing files; the supply-chain security policy is the procedural mechanism that constrains how those artefacts move between integrators and the entity.

  • REC-0008Gather Supply Chain InformationST0001
    addresses
    high
    derived

    Supply-chain reconnaissance maps the same end-to-end pathway the implementing regulation requires the entity to govern with a formal supply-chain security policy; that policy's confidentiality discipline is what prevents the adversary's pathway map from being assembled.

  • REC-0008.01Hardware ReconST0001
    addresses
    moderate
    derived

    Hardware-supply-chain reconnaissance focuses on components, screening, test history and configuration state; the supply-chain security policy is the procedural mechanism that scopes what the entity exposes about its parts pipeline.

  • REC-0008.02Software ReconST0001
    addresses
    moderate
    derived

    Software supply chains traverse the entity's supplier network; the supply-chain security policy governs the disclosure surface (vendor lists, dependency manifests, repository URLs) that recon harvests.

  • REC-0008.03Known VulnerabilitiesST0001
    addresses
    moderate
    derived

    Supply-chain security policy is the procedural lever for tracking supplier-disclosed vulnerabilities and pushing them through to remediation; weak supplier-side disclosure inflates the known-vulnerability recon surface.

  • REC-0008.04Business RelationshipsST0001
    addresses
    high
    derived

    Mapping primes, subs, integrators and operations partners is exactly the supply-chain topology the implementing regulation requires the entity to govern with a formal policy; that policy bounds how relationship metadata is exposed and protected.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.