nis2-impl

Annex 6.4.1

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (44)

Techniques referencing this article

  • DE-0001Disable Fault ManagementST0006
    addresses
    moderate
    derived

    FDIR/safing logic, watchdog parameters and limit/sanity-check thresholds are change-managed configuration; documented change procedures detect and block unauthorized disabling of fault management.

  • DE-0002.03Inhibit Spacecraft FunctionalityST0006
    addresses
    moderate
    derived

    On-board telemetry-publisher state, packet filters, rates and channel mute settings are change-managed configuration; documented procedures govern modification of these settings whether commanded or implanted.

  • DE-0003On-Board Values ObfuscationST0006
    addresses
    moderate
    derived

    Housekeeping counters, severity flags, mode selectors and crypto-state indicators are change-managed values; documented change procedures detect unauthorized obfuscation of these operator-visible truths.

  • DE-0003.01Vehicle Command Counter (VCC)ST0006
    addresses
    moderate
    derived

    VCC value alterations and command-path bypasses are change-management events governed by the implementing regulation's change-control procedures.

  • DE-0003.02Rejected Command CounterST0006
    addresses
    high
    derived

    Modifications to the rejected-command counter or its downlink representation are change-management events that must follow documented procedures.

  • DE-0003.03Command Receiver On/Off ModeST0006
    relates to
    high
    derived

    Toggling receiver enable states is a change-management event; documented procedures must govern configuration of receiver power and band selection.

  • Modifications to receiver AGC and signal-strength thresholds are change-managed configuration; documented procedures govern their alteration to prevent receivers from being detuned to refuse legitimate command traffic.

  • DE-0003.05Command Receiver Lock ModesST0006
    addresses
    moderate
    derived

    Configuration changes that alter receiver lock-state reporting (telemetry packet contents, severity flags) are change-management events governed by documented procedures.

  • DE-0003.06Telemetry Downlink ModesST0006
    addresses
    moderate
    derived

    Telemetry-mode switches, virtual-channel maps and APID selections are change-managed configuration; their modification follows documented procedures with review for mission-impact.

  • DE-0003.07Cryptographic ModesST0006
    addresses
    moderate
    derived

    Cryptographic mode changes are change-management events with significant security consequences; documented procedures with review and authorization govern such transitions.

  • DE-0003.09System Clock for EvasionST0006
    addresses
    moderate
    derived

    Clock writes and time-discipline source changes are change-management events with significant downstream effects; documented procedures must govern such modifications.

  • DE-0003.11Watchdog Timer (WDT) for EvasionST0006
    addresses
    moderate
    derived

    WDT parameter modification (timeouts, pet-task assignment) is change-managed configuration; documented procedures govern such modifications because their evidence-shaping effects are significant.

  • DE-0005Subvert Protections via Safe-ModeST0006
    addresses
    moderate
    derived

    Safe-mode profiles, contingency dictionaries and relaxed-check parameters are change-managed configuration; documented procedures must govern their definition and ensure the entry/exit transitions do not become evasion windows.

  • DE-0006Modify WhitelistST0006
    addresses
    high
    derived

    Whitelist-table modifications are change-management events; documented procedures must govern additions, removals and edits of whitelisted process/program identifiers.

  • DE-0008Evasion via BootkitST0006
    addresses
    moderate
    derived

    Boot-chain modification is change-managed; documented change procedures detect unauthorized alteration of boot ROM, early loaders and device-tree initialization.

  • EX-0003Modify Authentication ProcessST0004
    addresses
    high
    derived

    Change-management procedures govern modifications to flight or ground authentication services; they are the procedural envelope that detects and blocks unauthorized auth-process alteration.

  • EX-0004Compromise Boot MemoryST0004
    addresses
    high
    derived

    Boot ROM, bootloader configuration and early-init code are managed under change-management procedures; the implementing regulation requires the entity to control modifications to these crown-jewel components.

  • EX-0005.02Malicious Use of Hardware CommandsST0004
    addresses
    moderate
    derived

    Change-management procedures govern when and how hardware-level commands are issued in production; out-of-procedure issuance is exactly what an attacker exploits.

  • EX-0006Disable/Bypass EncryptionST0004
    addresses
    high
    derived

    Cryptographic configuration changes (encryption-on/off toggles, suite downgrades, key-rotation overrides) are change-management events that must follow documented procedures with review and authorization.

  • EX-0010.03RootkitST0004
    addresses
    moderate
    derived

    Change-management procedures govern modifications to flight-software processes, OS components and FSW frameworks; rootkit installation requires subverting that change pipeline.

  • EX-0010.04BootkitST0004
    addresses
    moderate
    derived

    Boot-chain artefacts (boot ROM, bootloader, init code) are managed under change-management procedures; the implementing regulation requires the entity to control modifications to these crown-jewel components and bootkit installation must subvert that pipeline.

  • EX-0012Modify On-Board ValuesST0004
    addresses
    high
    derived

    Modifications to live or persistent on-board values (registers, parameter tables, routing maps) are change-management events; the implementing regulation requires the entity to control changes to network-and-information-system parameters under documented procedures.

  • EX-0012.01RegistersST0004
    addresses
    moderate
    derived

    Register-level changes are change-management events; the implementing regulation requires controlled modification through documented procedures with review and authorization.

  • EX-0012.02Internal Routing TablesST0004
    addresses
    moderate
    derived

    Internal routing-table rewrites are configuration changes governed by change-management procedures; the implementing regulation requires controlled modification with documented review.

  • EX-0012.03Memory Write/LoadsST0004
    addresses
    high
    derived

    Direct memory-write/load operations are change-management events that must follow documented procedures; emergency procedures still require documentation and post-event review.

  • EX-0012.04App/Subscriber TablesST0004
    addresses
    moderate
    derived

    App/subscriber table modifications are configuration changes; change-management procedures govern release, modification and emergency edits to these tables.

  • EX-0012.05Scheduling AlgorithmST0004
    addresses
    moderate
    derived

    Scheduling-algorithm parameters (priorities, periods, deadlines) are change-managed configuration; modifications must follow documented procedures with review and rollback paths.

  • EX-0012.07Propulsion SubsystemST0004
    addresses
    high
    derived

    Propulsion parameters (thruster calibration, valve timing, safing thresholds) are change-managed configuration; alterations must follow documented procedures and be reviewed for their mission impact.

  • ADCS parameters (star-tracker catalogs, sensor alignments, gyro biases, estimator covariances) are change-managed configuration; modifications must flow through documented procedures.

  • EX-0012.09Electrical Power SubsystemST0004
    addresses
    high
    derived

    EPS parameters (bus voltage limits, charge curves, load-shed priorities) are change-managed configuration whose modifications must follow documented procedures with risk-assessment-driven review.

  • EX-0012.10Command & Data Handling SubsystemST0004
    addresses
    moderate
    derived

    C&DH tables and runtime values (opcode-to-handler maps, queue policies, telemetry collection lists) are change-managed configuration; modifications go through documented release and emergency-change procedures.

  • EX-0012.11Watchdog Timer (WDT)ST0004
    addresses
    high
    derived

    Watchdog-timer parameters (timeouts, reset actions, windowed bounds) are change-managed configuration; alterations must follow documented procedures because their mission-safety impact is significant.

  • EX-0012.12System ClockST0004
    addresses
    moderate
    derived

    Clock writes and time-base reconfiguration are change-management events with significant downstream effects on sequencing, anti-replay and navigation; documented procedures must govern such modifications.

  • EXF-0004Out-of-Band Communications LinkST0008
    addresses
    moderate
    derived

    Out-of-band link configuration changes (vendor/service modes, contingency profiles, beacon-content edits) are change-management events; documented procedures govern the activation and modification of these secondary paths.

  • EXF-0006Modify Communications ConfigurationST0008
    addresses
    moderate
    derived

    Communications-configuration alterations (carrier retuning, sidebands, modulation/coding profiles, virtual-channel/APID remaps, beacon content, regenerative-payload routing tables) are change-management events that must follow documented procedures with review and rollback paths.

  • EXF-0006.01Software Defined RadioST0008
    addresses
    moderate
    derived

    SDR firmware and waveform-profile changes are change-management events; documented procedures govern release, modification and emergency edits to these reconfigurable radios.

  • EXF-0006.02TransponderST0008
    addresses
    high
    derived

    Transponder configuration changes (input–output remap, translation-frequency shifts, polarization and gain edits, regenerative routing tables) are change-management events that must follow documented procedures.

  • Change-management procedures govern how SDR firmware, profiles and bitstreams are altered, reviewed and pushed to flight or ground SDRs — the procedural envelope an SDR-compromise adversary must subvert.

  • IA-0004.02ReceiverST0003
    addresses
    moderate
    derived

    Change-management procedures govern when backup receivers are enabled, reconfigured or cross-strapped, which are precisely the moments adversary access via the alternate path is most likely.

  • IA-0007.01Compromise On-Orbit UpdateST0003
    addresses
    high
    direct

    On-orbit update production is a change-management process; the implementing regulation requires the entity to apply documented procedures to control changes, including releases, modifications and emergency builds for flight software, configuration tables and ephemerides.

  • Change-management procedures govern flight-software, configuration table and parameter pushes during AIT and last-minute pad-side updates; ATLO compromises ride exactly that change pipeline.

  • IMP-0004DegradationST0009
    addresses
    moderate
    derived

    Unauthorized parameter changes that drive accelerated subsystem aging (over-charging batteries, repeated thermal cycling, propellant-budget waste) are change-management events; documented procedures must govern such modifications and surface anomalous patterns.

  • PER-0001Memory CompromiseST0005
    addresses
    high
    derived

    Memory-compromise persistence requires modifying boot ROM handoff vectors, first-stage code and initialization paths — all change-management-controlled artefacts under the implementing regulation's procedures.

  • PER-0004Replace Cryptographic KeysST0005
    addresses
    high
    derived

    Cryptographic-key replacement is a change-management event with dramatic security consequences; documented procedures with separation-of-duty review are the implementing-regulation lever that prevents single-operator key replacement under attacker direction.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.