nis2-impl

Annex 5.1.4

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (4)

Techniques referencing this article

  • EXF-0009Compromised Partner SiteST0008
    addresses
    high
    derived

    Direct-supplier security requirements (segmentation, monitoring discipline, vulnerability handling, incident-disclosure obligations) are the contractual mechanism that constrains how partner environments are operated; weak partner posture is the precondition for partner-site exfiltration.

  • IA-0001Compromise Supply ChainST0003
    addresses
    high
    derived

    Direct-supplier security requirements (vulnerability assessment, secure-development practices, disclosure obligations) are the procedural lever the entity uses to constrain which suppliers it accepts and to push security expectations down through the chain that supply-chain compromise traverses.

  • IA-0001.03Hardware Supply ChainST0003
    addresses
    moderate
    derived

    Direct-supplier security requirements (secure-handling practices, anti-counterfeit screening, tamper-evident packaging) are the contractual mechanism that constrains how hardware moves from foundry to final integration.

  • RD-0002.023rd Party Ground SystemST0002
    addresses
    high
    derived

    Supplier-quality requirements (vulnerability assessment, secure-development practices, disclosure obligations) are codified in the entity's supplier selection and contracting; weak third-party hygiene is what makes 3rd-party GS compromise viable.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.