nis2-impl

Annex 6.10.1

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (11)

Techniques referencing this article

  • EX-0005Exploit Hardware/Firmware CorruptionST0004
    addresses
    moderate
    derived

    Vulnerability-handling obligations require the entity to obtain information about hardware/firmware vulnerabilities and act on them, which shrinks the dwell time for exploitation through hardware/firmware corruption paths.

  • EX-0005.01Design FlawsST0004
    addresses
    high
    derived

    Vulnerability-handling and disclosure procedures require the entity to monitor design errata, evaluate impact and remediate or compensate; this is the procedural lever for design-flaw exploitation paths.

  • EX-0009Exploit Code FlawsST0004
    addresses
    high
    derived

    Code-flaw exploitation directly engages the vulnerability-handling-and-disclosure obligation: the entity must obtain vulnerability information for its flight and ground software, evaluate impact and apply remediation through its disclosure and treatment program.

  • EX-0009.01Flight SoftwareST0004
    addresses
    high
    derived

    Vulnerability-handling-and-disclosure obligations require the entity to obtain information about flight-software defects and act on them through coordinated remediation, which bounds the exploit window for code-flaw-class attacks against on-board parsers and autonomy logic.

  • EX-0009.02Operating SystemST0004
    addresses
    high
    derived

    Vulnerability-handling obligations cover OS-level defects (kernel issues, scheduler primitives, IPC vulnerabilities) and require the entity to monitor, evaluate impact and apply remediation through documented channels.

  • Known-vulnerability exploitation is precisely the threat the vulnerability-handling-and-disclosure obligation is established to bound: the entity must monitor public/private vulnerability sources for the COTS/FOSS components in its inventory and remediate before the adversary's recon-to-exploit window closes against it.

  • Vulnerability-handling obligations require the entity to obtain information about vulnerabilities in dependencies and toolchains, which is the metric that bounds dwell time for poisoned-dependency compromises.

  • IMP-0004DegradationST0009
    addresses
    moderate
    derived

    Degradation paths typically exploit unfixed defects in target subsystems; vulnerability-handling-and-disclosure procedures identify and remediate the weaknesses an attacker leverages to accelerate subsystem aging.

  • LM-0005Virtualization EscapeST0007
    addresses
    high
    derived

    Vulnerability-handling-and-disclosure procedures must apply to hypervisor and separation-kernel defects; coordinated remediation is the procedural mechanism that closes virtualization-escape paths once disclosed.

  • PER-0002BackdoorST0005
    addresses
    moderate
    derived

    Vulnerability-handling procedures govern coordinated disclosure of discovered backdoors and remediation timelines, which is the post-discovery procedural lever for closing them.

  • REC-0008.03Known VulnerabilitiesST0001
    addresses
    high
    direct

    Vulnerability-handling-and-disclosure obligations require the entity to obtain and act on vulnerability information for its systems; that procedural mechanism shrinks the gap between adversary recon of CVE catalogs and the entity's own remediation timeline.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.