nis2-impl

Annex 6.5.2

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (9)

Techniques referencing this article

  • Onboard SSA/SDA sensor-deception testing scope (proximity-sensor fusion under hostile inputs, dazzling/spoofing scenarios) is what Annex 6.5.2 requires the entity to define for the proximity-awareness portion of its security-testing program.

  • DE-0012Component CollusionST0006
    addresses
    high
    derived

    Component-collusion testing scope (cross-module behavioural analysis, integration-level security testing) is what Annex 6.5.2 requires the entity to define under risk-assessment-driven testing.

  • EX-0009Exploit Code FlawsST0004
    addresses
    high
    derived

    Primary mapping to Annex 6.5.1 (security-testing policy) for code-flaw exploitation implies Annex 6.5.2 obligations: the entity must establish need, scope and types of testing based on risk assessment, including the parser/library/driver classes a code-flaw adversary targets.

  • EX-0009.01Flight SoftwareST0004
    addresses
    high
    derived

    Flight-software command/telemetry handlers, table loaders and file-transfer services are exactly the test-scope items Annex 6.5.2 requires the entity to define under risk assessment, including fuzzing of parsers and integration testing on flatsats.

  • EX-0013.02Erroneous InputST0004
    addresses
    high
    derived

    Erroneous-input-flooding test scope (telecommand-parser fuzzing, malformed-frame ingestion testing) is exactly the procedural detail Annex 6.5.2 requires the entity to define under its testing policy.

  • EX-0014.03Sensor DataST0004
    addresses
    high
    derived

    Sensor-data-spoofing testing scope (sensor-fusion sanity checks, outlier-rejection logic, estimator robustness under fabricated measurements) is what Annex 6.5.2 requires the entity to define for its security-testing policy.

  • PER-0002BackdoorST0005
    addresses
    high
    derived

    Backdoor-detection testing scope (static analysis, taint analysis, integration-level authentication tests) is what Annex 6.5.2 requires the entity to define for its security-testing policy.

  • PER-0002.02Software BackdoorST0005
    addresses
    high
    derived

    Software-backdoor testing scope (taint analysis, behavioral testing of authentication paths, hidden-handler discovery) is what Annex 6.5.2 requires the entity to define under risk-assessment-driven testing.

  • REC-0006.02Security Testing ToolsST0001
    addresses
    moderate
    derived

    Security-testing-tools reconnaissance targets the same testing scope Annex 6.5.2 requires the entity to define; the policy that codifies what is tested also codifies what knowledge of testing must remain confidential.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.