Annex 6.10.1
Mapped SPARTA techniques (11)
Techniques referencing this article
Vulnerability-handling obligations require the entity to obtain information about hardware/firmware vulnerabilities and act on them, which shrinks the dwell time for exploitation through hardware/firmware corruption paths.
Vulnerability-handling and disclosure procedures require the entity to monitor design errata, evaluate impact and remediate or compensate; this is the procedural lever for design-flaw exploitation paths.
Code-flaw exploitation directly engages the vulnerability-handling-and-disclosure obligation: the entity must obtain vulnerability information for its flight and ground software, evaluate impact and apply remediation through its disclosure and treatment program.
Vulnerability-handling-and-disclosure obligations require the entity to obtain information about flight-software defects and act on them through coordinated remediation, which bounds the exploit window for code-flaw-class attacks against on-board parsers and autonomy logic.
Vulnerability-handling obligations cover OS-level defects (kernel issues, scheduler primitives, IPC vulnerabilities) and require the entity to monitor, evaluate impact and apply remediation through documented channels.
Known-vulnerability exploitation is precisely the threat the vulnerability-handling-and-disclosure obligation is established to bound: the entity must monitor public/private vulnerability sources for the COTS/FOSS components in its inventory and remediate before the adversary's recon-to-exploit window closes against it.
Vulnerability-handling obligations require the entity to obtain information about vulnerabilities in dependencies and toolchains, which is the metric that bounds dwell time for poisoned-dependency compromises.
Degradation paths typically exploit unfixed defects in target subsystems; vulnerability-handling-and-disclosure procedures identify and remediate the weaknesses an attacker leverages to accelerate subsystem aging.
Vulnerability-handling-and-disclosure procedures must apply to hypervisor and separation-kernel defects; coordinated remediation is the procedural mechanism that closes virtualization-escape paths once disclosed.
Vulnerability-handling procedures govern coordinated disclosure of discovered backdoors and remediation timelines, which is the post-discovery procedural lever for closing them.
Vulnerability-handling-and-disclosure obligations require the entity to obtain and act on vulnerability information for its systems; that procedural mechanism shrinks the gap between adversary recon of CVE catalogs and the entity's own remediation timeline.