nis2-impl

Annex 6.5.3

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (9)

Techniques referencing this article

  • Annex 6.5.3 review-cadence applies to proximity-sensor testing scope to keep pace with adversary-deception capability evolution.

  • DE-0012Component CollusionST0006
    addresses
    moderate
    derived

    Annex 6.5.3 review-cadence ensures cross-module testing scope evolves as supplier composition and module interactions change.

  • EX-0009Exploit Code FlawsST0004
    addresses
    moderate
    derived

    Annex 6.5.3 requires planned-interval review of testing policies; testing scope must keep pace with the evolving code-flaw threat surface.

  • EX-0009.01Flight SoftwareST0004
    addresses
    moderate
    derived

    Annex 6.5.3 review-cadence obligation ensures FSW security testing policy is kept current as flight-software code base, dependencies and threat model evolve.

  • EX-0013.02Erroneous InputST0004
    addresses
    moderate
    derived

    Annex 6.5.3 review-cadence ensures erroneous-input testing scope stays aligned with parser-evolution and protocol changes.

  • EX-0014.03Sensor DataST0004
    addresses
    moderate
    derived

    Sensor-data spoofing reaches estimation and control through several distinct injection surfaces (electrical interfaces, optical blinding of trackers, magnetic, and crafted packets at sensor gateways), so the planned-interval review obligation in Annex 6.5.3 is the duty that keeps the testing policy's coverage current as those surfaces are characterized. The obligation is to review and where appropriate update the testing policy itself, which is governance over what gets tested rather than detection of the fabricated measurements, supporting an addresses relationship at moderate confidence.

  • PER-0002BackdoorST0005
    addresses
    moderate
    derived

    Annex 6.5.3 review-cadence keeps backdoor-detection testing scope current as code base, supplier-mix and detection-tool capabilities evolve.

  • PER-0002.02Software BackdoorST0005
    addresses
    moderate
    derived

    Annex 6.5.3 review-cadence ensures software-backdoor testing scope tracks code-base evolution and disclosure-driven new-attack patterns.

  • REC-0006.02Security Testing ToolsST0001
    addresses
    moderate
    derived

    Annex 6.5.3 review-cadence keeps the testing-policy and tool inventory current, which constrains the recon adversary's blind-spot map of the entity's test-tool gaps.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.