nis2-impl

Annex 5.1.6

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (23)

Techniques referencing this article

  • DE-0012Component CollusionST0006
    addresses
    high
    derived

    Component-collusion compromise rides through coordinated supply-chain manipulation across multiple suppliers; Annex 5.1.6 ongoing monitoring (correlating signals across the supplier population) is the procedural mechanism that surfaces such cross-supplier collusion patterns.

  • EXF-0008Compromised Developer SiteST0008
    addresses
    high
    derived

    Developer-site suppliers (contractors, integrators, partner dev environments) require Annex 5.1.6 ongoing monitoring because dev-site compromise typically rides through gradually deteriorating supplier-side security posture.

  • EXF-0009Compromised Partner SiteST0008
    addresses
    high
    derived

    Partner-site exfiltration paths are best closed by Annex 5.1.6 ongoing monitoring of partner-side security posture, breach disclosures and policy compliance.

  • EXF-0010Payload Communication ChannelST0008
    addresses
    moderate
    derived

    Payload vendors and gateway operators handle ongoing communications channels; Annex 5.1.6 monitoring detects supplier-side incidents that could open covert payload-channel exfiltration.

  • IA-0001Compromise Supply ChainST0003
    addresses
    high
    derived

    Primary mapping to Annex 5.1.1 (supply-chain policy) for supply-chain compromise implies Annex 5.1.6 ongoing monitoring: the entity must monitor and act on supplier-conduct, vulnerability-disclosure and policy-deviation signals across the chain.

  • Software-dependency and dev-tool suppliers (registries, foundations, CI providers) are exactly the population where Annex 5.1.6 ongoing monitoring detects upstream compromise via reports of dependency confusion, signing-key incidents and registry tampering.

  • IA-0001.02Software Supply ChainST0003
    addresses
    high
    derived

    Software suppliers (build vendors, package signers, OTA distributors) require Annex 5.1.6 ongoing monitoring; the entity's supplier-quality posture depends on continuous oversight rather than only initial selection.

  • IA-0001.03Hardware Supply ChainST0003
    addresses
    high
    derived

    Hardware suppliers (foundries, board houses, IC integrators) require Annex 5.1.6 ongoing monitoring across lots, lifecycle changes and supplier-disclosed errata to surface tampering and counterfeit risk over time.

  • SDR vendors and waveform suppliers require Annex 5.1.6 ongoing monitoring because reconfigurable radios depend on continuous integrity oversight of vendor-supplied bitstreams and configuration profiles.

  • IA-0006Compromise Hosted PayloadST0003
    addresses
    high
    derived

    Hosted-payload providers maintain ongoing access via gateway interfaces; Annex 5.1.6 monitoring detects supplier-side incidents and posture changes that would expose the host bus to payload-side compromise.

  • IA-0009Trusted RelationshipST0003
    addresses
    high
    derived

    Trusted-relationship counterparties hold persistent connections; Annex 5.1.6 monitoring is the procedural lever that detects deteriorating posture, breaches and policy non-compliance among those counterparties before they are weaponized against the entity.

  • Mission collaborators (universities, science ops centers, international partners) require Annex 5.1.6 ongoing monitoring of cross-org credential hygiene and incident-disclosure compliance.

  • IA-0009.02VendorST0003
    addresses
    high
    derived

    Vendors with persistent admin access require Annex 5.1.6 ongoing monitoring of their security posture, incident disclosures and remote-access usage patterns.

  • IA-0009.03User SegmentST0003
    addresses
    moderate
    derived

    User-segment suppliers (terminal vendors, customer-gateway providers, downstream processors) require Annex 5.1.6 ongoing monitoring as user-segment compromise rides through their security posture.

  • IA-0011Auxiliary Device CompromiseST0003
    addresses
    moderate
    derived

    Auxiliary-device suppliers (EGSE vendors, calibration tooling, external storage) require Annex 5.1.6 ongoing monitoring because firmware updates and tooling revisions continuously reshape the auxiliary-device threat surface.

  • ATLO suppliers (AIT facility, integrator, pad-side service providers) require Annex 5.1.6 ongoing monitoring because each launch campaign exposes the entity to fresh supplier-side security posture variations.

  • IA-0013Compromise Host SpacecraftST0003
    addresses
    moderate
    derived

    Host-spacecraft operators are persistent-supplier counterparties; Annex 5.1.6 monitoring detects host-side posture changes that would expose the entity's hosted payload to host-bus compromise.

  • LM-0004Visiting Vehicle Interface(s)ST0007
    addresses
    moderate
    derived

    Visiting-vehicle operators (cargo, OSAM, crewed) require Annex 5.1.6 ongoing monitoring because each rendezvous campaign exposes the entity to a fresh assessment of partner-vehicle security posture.

  • LM-0006Launch Vehicle InterfaceST0007
    addresses
    moderate
    derived

    Launch-vehicle providers and EGSE-network operators require Annex 5.1.6 ongoing monitoring because launch-campaign cadence repeatedly exposes the entity to provider posture changes.

  • LM-0006.01Rideshare PayloadST0007
    addresses
    moderate
    derived

    Rideshare cohabitants and deployer operators require Annex 5.1.6 ongoing monitoring because shared-infrastructure threats are determined by other-payload supplier posture.

  • PER-0002.01Hardware BackdoorST0005
    addresses
    high
    derived

    Hardware backdoor planting rides through silicon, board and firmware suppliers; Annex 5.1.6 ongoing monitoring of those suppliers' disclosed errata, supply changes and incident reports is essential for catching backdoors that ship signed and provenance-clean.

  • PER-0002.02Software BackdoorST0005
    addresses
    high
    derived

    Software backdoor planting through software suppliers requires Annex 5.1.6 ongoing monitoring of supplier-side build-pipeline integrity, signing-key incidents and disclosure compliance.

  • RD-0002.023rd Party Ground SystemST0002
    addresses
    high
    derived

    Third-party ground-system providers maintain ongoing connections to the entity's mission systems; Annex 5.1.6 monitoring of those providers' security posture and incident-disclosure compliance is essential to detect compromise that could be used as adversary infrastructure against the entity.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.