nis2-impl

Annex 6.6.1

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (11)

Techniques referencing this article

  • EX-0003Modify Authentication ProcessST0004
    addresses
    moderate
    derived

    Patch-management procedures ensure that authentication-related fixes are applied through controlled channels; out-of-band modifications to auth logic should fail patch-integrity checks.

  • EX-0009Exploit Code FlawsST0004
    addresses
    high
    derived

    Security-patch management procedures determine how known code-flaw fixes are deployed to the entity's network and information systems; the deployment cadence is the metric that bounds the exploit window.

  • EX-0009.01Flight SoftwareST0004
    addresses
    moderate
    derived

    Security-patch management procedures govern the deployment of fixes to flight software once defects are identified, determining the operational dwell time before remediation.

  • EX-0009.02Operating SystemST0004
    addresses
    high
    derived

    Security-patch management procedures bound how quickly OS-layer fixes are validated, packaged and deployed to flight or ground systems running the affected kernels.

  • Security-patch management procedures determine the cadence at which known vulnerabilities in COTS/FOSS components are closed, the metric the technique attempts to outrun.

  • EX-0010Malicious CodeST0004
    addresses
    moderate
    derived

    Security-patch-management procedures, by constraining how legitimate code is delivered, also serve as the procedural envelope that out-of-band malicious-code introduction must subvert.

  • IA-0001.02Software Supply ChainST0003
    addresses
    moderate
    derived

    Security-patch management procedures are the lever that ensures swapped or maliciously-signed update packages are detected and remediated through coherent change-management discipline rather than installed silently.

  • IA-0002Compromise Software Defined RadioST0003
    addresses
    moderate
    derived

    Security-patch management for SDR firmware and waveform packages is the lever that closes the SDR-compromise opportunity before it is exploited.

  • IA-0007.01Compromise On-Orbit UpdateST0003
    addresses
    high
    derived

    Security-patch management procedures govern how security updates are produced, signed and deployed to flight assets; they are the procedural envelope around the on-orbit update pipeline.

  • LM-0005Virtualization EscapeST0007
    addresses
    moderate
    derived

    Security-patch management procedures determine how quickly hypervisor defects are deployed in flight or ground systems; deployment cadence bounds the exploit window for disclosed escape paths.

  • REC-0008.03Known VulnerabilitiesST0001
    addresses
    high
    direct

    Security-patch management procedures determine how quickly publicly-known vulnerabilities are closed in the entity's systems, which is the metric the adversary's known-vulnerability reconnaissance is trying to exploit before remediation.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.