nis2-impl

Annex 6.5.1

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (9)

Techniques referencing this article

  • Security-testing policies should exercise sensor-fusion sanity checks and outlier-rejection logic; the proximity-sensor deception this technique describes exploits gaps in those onboard fusion mechanisms.

  • DE-0012Component CollusionST0006
    addresses
    moderate
    derived

    Security-testing procedures (integration testing, behavioural testing across module boundaries) are the procedural mechanism that surfaces collusive component interactions before they reach production.

  • EX-0009Exploit Code FlawsST0004
    addresses
    high
    derived

    Security-testing policy and procedures (static analysis, fuzzing, integration testing) are the procedural mechanism that surfaces code flaws before they reach production.

  • EX-0009.01Flight SoftwareST0004
    addresses
    high
    derived

    Security-testing policy and procedures (static analysis, fuzzing of command parsers and table loaders, integration testing on flatsats) are the procedural mechanism that surfaces flight-software flaws before flight.

  • EX-0013.02Erroneous InputST0004
    addresses
    moderate
    derived

    Security-testing policies (fuzzing of telecommand parsers and bus-message decoders) surface the parser fragility erroneous-input flooding exploits, before flight.

  • EX-0014.03Sensor DataST0004
    addresses
    moderate
    derived

    Security testing of estimation pipelines, sensor-fusion sanity checks and outlier-rejection logic surfaces fragility that fabricated sensor data exploits.

  • PER-0002BackdoorST0005
    addresses
    high
    derived

    Security-testing policy and procedures (static analysis, taint analysis, behavioral testing of authentication paths) are the procedural mechanism that surfaces backdoors before they reach production.

  • PER-0002.02Software BackdoorST0005
    addresses
    high
    derived

    Security-testing procedures (static analysis, taint analysis, integration-level authentication tests) surface software backdoors before they reach production.

  • REC-0006.02Security Testing ToolsST0001
    addresses
    high
    direct

    Security-testing tools and policies are exactly what the implementing regulation requires the entity to formalize; the same policy that codifies what is tested also codifies what knowledge of testing must remain confidential.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.