nis2-impl

Annex 5.1.7

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (24)

Techniques referencing this article

  • DE-0012Component CollusionST0006
    addresses
    high
    derived

    Annex 5.1.7 follow-up procedures convert cross-supplier collusion signals into integration-test reinforcement and supplier-replacement actions.

  • EXF-0008Compromised Developer SiteST0008
    addresses
    moderate
    derived

    Annex 5.1.7 reporting and follow-up convert dev-site supplier monitoring signals into pre-launch verification actions and supplier remediation.

  • EXF-0009Compromised Partner SiteST0008
    addresses
    high
    derived

    Annex 5.1.7 reporting and follow-up are the procedural mechanism that converts partner-side monitoring signals into contract action, partner replacement or incident coordination.

  • EXF-0010Payload Communication ChannelST0008
    addresses
    moderate
    derived

    Annex 5.1.7 follow-up procedures convert payload-vendor monitoring signals into channel-isolation and gateway-restriction actions.

  • IA-0001Compromise Supply ChainST0003
    addresses
    moderate
    derived

    Continuous monitoring of supplier conduct, vulnerability disclosures and contractual compliance is the procedural mechanism that surfaces a supplier becoming compromised before delivered artefacts reach flight or ground systems.

  • Annex 5.1.7 follow-up procedures are the lever that converts monitoring signals on dependency or tooling suppliers into remediation actions (mirror updates, supplier replacement, contract amendment).

  • IA-0001.02Software Supply ChainST0003
    addresses
    high
    derived

    Annex 5.1.7 reporting and follow-up obligations operationalize the response to software-supplier monitoring signals.

  • IA-0001.03Hardware Supply ChainST0003
    addresses
    moderate
    derived

    Annex 5.1.7 follow-up procedures convert hardware-supplier monitoring signals into supplier audits, lot-screening reinforcement or supply replacement.

  • IA-0002Compromise Software Defined RadioST0003
    addresses
    moderate
    derived

    Annex 5.1.7 follow-up converts SDR-vendor monitoring signals into bitstream-integrity actions and supplier remediation.

  • IA-0006Compromise Hosted PayloadST0003
    addresses
    moderate
    derived

    Annex 5.1.7 reporting and follow-up procedures operationalize hosted-payload provider monitoring, linking supplier signals to host-bus protective actions.

  • IA-0009Trusted RelationshipST0003
    addresses
    high
    derived

    Annex 5.1.7 reporting and follow-up procedures convert third-party monitoring signals into access-rights review, contract action and incident-coordination escalations.

  • This technique delivers attacker-modified calibration scripts, configuration tables, and payload tasks into mission workflows through collaborator ICT services, and Annex 5.1.7 obliges entities to review incidents related to those suppliers' ICT products and services and to analyse the risks presented by changes to them, taking timely mitigating measures. That duty to scrutinise supplier-originated changes and incidents is what makes the article relevant to compromised-partner artifacts traversing sanctioned paths.

  • IA-0009.02VendorST0003
    addresses
    high
    derived

    Annex 5.1.7 follow-up procedures operationalize vendor-monitoring signals into vendor-access review, MFA-enforcement adjustments and contract remediation.

  • IA-0009.03User SegmentST0003
    addresses
    moderate
    derived

    Annex 5.1.7 follow-up procedures convert user-segment monitoring signals into segmentation, access-restriction and supplier-replacement actions.

  • IA-0011Auxiliary Device CompromiseST0003
    addresses
    moderate
    derived

    Annex 5.1.7 reporting cadence captures auxiliary-device supplier signals and drives integration-environment remediation.

  • Annex 5.1.7 reporting and follow-up procedures convert ATLO-supplier monitoring signals into AIT-environment hardening and pre-launch verification actions.

  • IA-0013Compromise Host SpacecraftST0003
    addresses
    moderate
    derived

    Annex 5.1.7 follow-up procedures operationalize host-operator monitoring signals into segmentation, telemetry-isolation and contractual responses.

  • LM-0004Visiting Vehicle Interface(s)ST0007
    addresses
    moderate
    derived

    Annex 5.1.7 follow-up procedures convert visiting-vehicle monitoring signals into pre-rendezvous verification actions and operator-side trust-boundary adjustments.

  • LM-0006Launch Vehicle InterfaceST0007
    addresses
    moderate
    derived

    Annex 5.1.7 follow-up procedures convert launch-provider monitoring signals into umbilical-handling and EGSE-network protective actions.

  • LM-0006.01Rideshare PayloadST0007
    addresses
    moderate
    derived

    Annex 5.1.7 follow-up procedures translate rideshare monitoring signals into deployer-controller isolation and shared-bus protective actions.

  • PER-0002.01Hardware BackdoorST0005
    addresses
    moderate
    derived

    Annex 5.1.7 follow-up procedures convert hardware-supplier monitoring signals into lot-screening reinforcement, supplier audit and contractual remediation.

  • PER-0002.02Software BackdoorST0005
    addresses
    moderate
    derived

    A software backdoor is hidden code that reaches flight applications, drivers, gateway processors, or loader utilities through a supplier-delivered ICT product or a later change to one, which is exactly what Annex 5.1.7(d) requires entities to catch by analysing the risks presented by changes related to suppliers' ICT products and taking mitigating measures. Point (b)'s duty to review incidents related to those ICT products and services covers the case where a planted command handler or alternate authentication path is reported, giving this article a specific hold on backdoors that enter through the supply chain rather than generic supplier oversight.

  • RD-0002.023rd Party Ground SystemST0002
    addresses
    moderate
    derived

    Annex 5.1.7 reporting and follow-up are the operational lever that converts third-party-GS monitoring signals into provider replacement, contract amendment or incident-response coordination.

  • REC-0008Gather Supply Chain InformationST0001
    addresses
    moderate
    derived

    Continuous monitoring of supplier conduct and contractual provisions is the procedural lever that controls how supply-chain information is distributed and protected, including from third-party leakage.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.