Annex 5.1.6
Mapped SPARTA techniques (23)
Techniques referencing this article
Component-collusion compromise rides through coordinated supply-chain manipulation across multiple suppliers; Annex 5.1.6 ongoing monitoring (correlating signals across the supplier population) is the procedural mechanism that surfaces such cross-supplier collusion patterns.
Developer-site suppliers (contractors, integrators, partner dev environments) require Annex 5.1.6 ongoing monitoring because dev-site compromise typically rides through gradually deteriorating supplier-side security posture.
Partner-site exfiltration paths are best closed by Annex 5.1.6 ongoing monitoring of partner-side security posture, breach disclosures and policy compliance.
Payload vendors and gateway operators handle ongoing communications channels; Annex 5.1.6 monitoring detects supplier-side incidents that could open covert payload-channel exfiltration.
Primary mapping to Annex 5.1.1 (supply-chain policy) for supply-chain compromise implies Annex 5.1.6 ongoing monitoring: the entity must monitor and act on supplier-conduct, vulnerability-disclosure and policy-deviation signals across the chain.
Software-dependency and dev-tool suppliers (registries, foundations, CI providers) are exactly the population where Annex 5.1.6 ongoing monitoring detects upstream compromise via reports of dependency confusion, signing-key incidents and registry tampering.
Software suppliers (build vendors, package signers, OTA distributors) require Annex 5.1.6 ongoing monitoring; the entity's supplier-quality posture depends on continuous oversight rather than only initial selection.
Hardware suppliers (foundries, board houses, IC integrators) require Annex 5.1.6 ongoing monitoring across lots, lifecycle changes and supplier-disclosed errata to surface tampering and counterfeit risk over time.
SDR vendors and waveform suppliers require Annex 5.1.6 ongoing monitoring because reconfigurable radios depend on continuous integrity oversight of vendor-supplied bitstreams and configuration profiles.
Hosted-payload providers maintain ongoing access via gateway interfaces; Annex 5.1.6 monitoring detects supplier-side incidents and posture changes that would expose the host bus to payload-side compromise.
Trusted-relationship counterparties hold persistent connections; Annex 5.1.6 monitoring is the procedural lever that detects deteriorating posture, breaches and policy non-compliance among those counterparties before they are weaponized against the entity.
Mission collaborators (universities, science ops centers, international partners) require Annex 5.1.6 ongoing monitoring of cross-org credential hygiene and incident-disclosure compliance.
Vendors with persistent admin access require Annex 5.1.6 ongoing monitoring of their security posture, incident disclosures and remote-access usage patterns.
User-segment suppliers (terminal vendors, customer-gateway providers, downstream processors) require Annex 5.1.6 ongoing monitoring as user-segment compromise rides through their security posture.
Auxiliary-device suppliers (EGSE vendors, calibration tooling, external storage) require Annex 5.1.6 ongoing monitoring because firmware updates and tooling revisions continuously reshape the auxiliary-device threat surface.
ATLO suppliers (AIT facility, integrator, pad-side service providers) require Annex 5.1.6 ongoing monitoring because each launch campaign exposes the entity to fresh supplier-side security posture variations.
Host-spacecraft operators are persistent-supplier counterparties; Annex 5.1.6 monitoring detects host-side posture changes that would expose the entity's hosted payload to host-bus compromise.
Visiting-vehicle operators (cargo, OSAM, crewed) require Annex 5.1.6 ongoing monitoring because each rendezvous campaign exposes the entity to a fresh assessment of partner-vehicle security posture.
Launch-vehicle providers and EGSE-network operators require Annex 5.1.6 ongoing monitoring because launch-campaign cadence repeatedly exposes the entity to provider posture changes.
Rideshare cohabitants and deployer operators require Annex 5.1.6 ongoing monitoring because shared-infrastructure threats are determined by other-payload supplier posture.
Hardware backdoor planting rides through silicon, board and firmware suppliers; Annex 5.1.6 ongoing monitoring of those suppliers' disclosed errata, supply changes and incident reports is essential for catching backdoors that ship signed and provenance-clean.
Software backdoor planting through software suppliers requires Annex 5.1.6 ongoing monitoring of supplier-side build-pipeline integrity, signing-key incidents and disclosure compliance.
Third-party ground-system providers maintain ongoing connections to the entity's mission systems; Annex 5.1.6 monitoring of those providers' security posture and incident-disclosure compliance is essential to detect compromise that could be used as adversary infrastructure against the entity.