Annex 5.1.7
Mapped SPARTA techniques (24)
Techniques referencing this article
Annex 5.1.7 follow-up procedures convert cross-supplier collusion signals into integration-test reinforcement and supplier-replacement actions.
Annex 5.1.7 reporting and follow-up convert dev-site supplier monitoring signals into pre-launch verification actions and supplier remediation.
Annex 5.1.7 reporting and follow-up are the procedural mechanism that converts partner-side monitoring signals into contract action, partner replacement or incident coordination.
Annex 5.1.7 follow-up procedures convert payload-vendor monitoring signals into channel-isolation and gateway-restriction actions.
Continuous monitoring of supplier conduct, vulnerability disclosures and contractual compliance is the procedural mechanism that surfaces a supplier becoming compromised before delivered artefacts reach flight or ground systems.
Annex 5.1.7 follow-up procedures are the lever that converts monitoring signals on dependency or tooling suppliers into remediation actions (mirror updates, supplier replacement, contract amendment).
Annex 5.1.7 reporting and follow-up obligations operationalize the response to software-supplier monitoring signals.
Annex 5.1.7 follow-up procedures convert hardware-supplier monitoring signals into supplier audits, lot-screening reinforcement or supply replacement.
Annex 5.1.7 follow-up converts SDR-vendor monitoring signals into bitstream-integrity actions and supplier remediation.
Annex 5.1.7 reporting and follow-up procedures operationalize hosted-payload provider monitoring, linking supplier signals to host-bus protective actions.
Annex 5.1.7 reporting and follow-up procedures convert third-party monitoring signals into access-rights review, contract action and incident-coordination escalations.
This technique delivers attacker-modified calibration scripts, configuration tables, and payload tasks into mission workflows through collaborator ICT services, and Annex 5.1.7 obliges entities to review incidents related to those suppliers' ICT products and services and to analyse the risks presented by changes to them, taking timely mitigating measures. That duty to scrutinise supplier-originated changes and incidents is what makes the article relevant to compromised-partner artifacts traversing sanctioned paths.
Annex 5.1.7 follow-up procedures operationalize vendor-monitoring signals into vendor-access review, MFA-enforcement adjustments and contract remediation.
Annex 5.1.7 follow-up procedures convert user-segment monitoring signals into segmentation, access-restriction and supplier-replacement actions.
Annex 5.1.7 reporting cadence captures auxiliary-device supplier signals and drives integration-environment remediation.
Annex 5.1.7 reporting and follow-up procedures convert ATLO-supplier monitoring signals into AIT-environment hardening and pre-launch verification actions.
Annex 5.1.7 follow-up procedures operationalize host-operator monitoring signals into segmentation, telemetry-isolation and contractual responses.
Annex 5.1.7 follow-up procedures convert visiting-vehicle monitoring signals into pre-rendezvous verification actions and operator-side trust-boundary adjustments.
Annex 5.1.7 follow-up procedures convert launch-provider monitoring signals into umbilical-handling and EGSE-network protective actions.
Annex 5.1.7 follow-up procedures translate rideshare monitoring signals into deployer-controller isolation and shared-bus protective actions.
Annex 5.1.7 follow-up procedures convert hardware-supplier monitoring signals into lot-screening reinforcement, supplier audit and contractual remediation.
A software backdoor is hidden code that reaches flight applications, drivers, gateway processors, or loader utilities through a supplier-delivered ICT product or a later change to one, which is exactly what Annex 5.1.7(d) requires entities to catch by analysing the risks presented by changes related to suppliers' ICT products and taking mitigating measures. Point (b)'s duty to review incidents related to those ICT products and services covers the case where a planted command handler or alternate authentication path is reported, giving this article a specific hold on backdoors that enter through the supply chain rather than generic supplier oversight.
Annex 5.1.7 reporting and follow-up are the operational lever that converts third-party-GS monitoring signals into provider replacement, contract amendment or incident-response coordination.
Continuous monitoring of supplier conduct and contractual provisions is the procedural lever that controls how supply-chain information is distributed and protected, including from third-party leakage.