nis2-impl

Annex 6.7.1

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (30)

Techniques referencing this article

  • DE-0002Disrupt or Deceive DownlinkST0006
    addresses
    moderate
    derived

    Network-security obligations cover the ground-side telemetry pipeline (reception, processing, display); the protections that resist downlink disruption ride on those network-security measures.

  • DE-0002.01Inhibit Ground System FunctionalityST0006
    addresses
    moderate
    derived

    Inhibiting ground-system functionality acts on the entity's ground-segment networks and processing chain; network-security obligations cover the protections (boundary control, gateway monitoring, integrity verification of telemetry processing) that resist this attack.

  • Ground-based SDA pipelines are part of the entity's network-and-information-systems estate (or those of its SDA partners); network-security obligations cover the protection of observational feeds, catalog services and tracking-center networks.

  • EX-0001.02Bus Traffic ReplayST0004
    addresses
    moderate
    derived

    Internal command/data buses (1553, SpaceWire, custom) are part of the network-and-information-systems estate; network-security measures apply to the protection of bus traffic from arbitrary injection or replay.

  • Network-security measures must remain in force across mode transitions; safe-mode does not exempt the entity from network-protection obligations, which is the implementing-regulation lever that closes the reduced-protection window the technique exploits.

  • EX-0013FloodingST0004
    addresses
    moderate
    derived

    Network-security obligations cover protection of links and processing paths from saturation; rate limiting, traffic shaping and ingress filtering at gateways are the network-security controls that absorb or shed flooding traffic.

  • EX-0013.02Erroneous InputST0004
    addresses
    moderate
    derived

    Network-security obligations cover ingress hardening of receivers and parsers against malformed and noise inputs; this is the protective layer that prevents erroneous-input flooding from becoming a denial event.

  • EX-0014.02Bus Traffic SpoofingST0004
    addresses
    moderate
    derived

    Internal command/data buses are part of the entity's network estate; network-security obligations cover the protection of bus traffic from forged-frame injection through authentication, source restriction and segmentation.

  • EX-0014.03Sensor DataST0004
    addresses
    moderate
    derived

    Network-security obligations cover the protection of sensor-data interfaces between sensors and FSW; integrity protection on those interfaces resists fabricated-measurement injection.

  • EXF-0002.03Traffic Analysis AttacksST0008
    addresses
    moderate
    derived

    Network-security obligations cover protection of traffic flows including measures that resist traffic analysis (cover traffic, padding, link-load smoothing) where appropriate to the risk profile.

  • EXF-0003Signal InterceptionST0008
    addresses
    moderate
    derived

    Network-security obligations cover the protection of mission traffic in transit on ground LANs/WANs and across the space link; encryption, link-protection and integrity controls are the network-security measures that resist signal interception.

  • EXF-0003.01Uplink ExfiltrationST0008
    addresses
    moderate
    derived

    Network-security obligations cover the protection of uplink command traffic; link-encryption and integrity protection are the network-security measures that resist uplink-side interception of telecommand frames and file uploads.

  • EXF-0003.02Downlink ExfiltrationST0008
    addresses
    moderate
    derived

    Network-security obligations cover protection of downlink traffic on space-link and ground-side networks; link-layer encryption, integrity verification and signal-protection measures are the network-security measures that resist offline reconstruction of recorded downlinks.

  • EXF-0004Out-of-Band Communications LinkST0008
    addresses
    moderate
    derived

    Out-of-band communications links (rekeying channels, emergency commanding, beacons, custodial crosslinks) are part of the entity's network-and-information-systems estate; network-security obligations apply equally to secondary purpose-built channels and require the same protection as the primary TT&C.

  • EXF-0005Proximity OperationsST0008
    addresses
    moderate
    derived

    Network-security obligations cover protection of crosslink and inter-vehicle traffic that a proximate adversary can observe; link-encryption and source authentication on those flows resist exfiltration value.

  • EXF-0007Compromised Ground SystemST0008
    addresses
    moderate
    derived

    Network-security obligations cover the entire ground-segment estate where compromised-ground-system exfiltration occurs (operator workstations, mission-control servers, baseband chains, archive databases); boundary protection, gateway monitoring and traffic-egress controls are the network-security measures that bound mass exfiltration.

  • EXF-0009Compromised Partner SiteST0008
    addresses
    moderate
    derived

    Cross-organization links (partner-station to MOC, processing partner to operator) are part of the entity's network-and-information-systems estate; network-security obligations apply to those gateways and resist man-in-the-middle exfiltration.

  • IA-0003Crosslink via Compromised NeighborST0003
    addresses
    moderate
    derived

    Inter-satellite link traffic between vehicles is part of the entity's network-and-information-systems estate; network-security obligations apply to the protection of crosslink data flows, route filtering and authentication of remote peers.

  • IA-0004Secondary/Backup Communication ChannelST0003
    addresses
    moderate
    derived

    Backup TT&C and contingency MOC paths are part of the entity's network-and-information-systems estate; network-security obligations apply equally to the primary and the alternate, including cross-strapped paths.

  • IA-0007Compromise Ground SystemST0003
    addresses
    moderate
    derived

    The ground segment is the entity's primary network-and-information-systems estate; network-security measures (boundary protection, gateway hardening, monitoring of mission-control traffic) are the obligations under which the entity blocks ground-system compromise paths.

  • IA-0008Rogue External EntityST0003
    addresses
    moderate
    derived

    Network-security measures cover the air interface as part of the entity's network-and-information-systems estate; protection of the link from injection is a network-security obligation.

  • IA-0008.01Rogue Ground StationST0003
    addresses
    moderate
    derived

    Network-security obligations apply to RF-link protection, including the cryptographic and protocol measures that resist injection from arbitrary transmitters.

  • IA-0010Unauthorized Access During Safe-ModeST0003
    addresses
    moderate
    derived

    Network-security measures must remain in force across mode transitions; safe-mode is a network-security context where reduced visibility creates the exact opportunity this technique exploits.

  • IMP-0006TheftST0009
    addresses
    moderate
    derived

    Network-security obligations cover the protection of mission data in transit (encryption, integrity, egress monitoring), reducing the value of intercepted or exfiltrated traffic offline.

  • LM-0003Constellation Hopping via CrosslinkST0007
    addresses
    moderate
    derived

    Network-security obligations cover crosslink traffic between satellites; protection of routing updates, service advertisements and inter-vehicle data flows is part of the entity's network-security envelope.

  • PER-0003Ground System PresenceST0005
    addresses
    moderate
    derived

    Network-security measures protect operator workstations, mission-control servers and gateway equipment from persistent attacker presence; the network-security obligations are the protective envelope around the ground-segment infrastructure this technique inhabits.

  • RD-0002Compromise InfrastructureST0002
    addresses
    moderate
    derived

    Network-security obligations are the protection envelope around the entity's infrastructure; an adversary compromising existing infrastructure for staging is acting against precisely the controls Annex 6.7 requires the entity to maintain.

  • Network security obligations apply to the comms architecture and the protection of comms-configuration management — recon for the RF posture is fundamentally a network-security observable.

  • REC-0005.01Uplink Intercept EavesdroppingST0001
    addresses
    moderate
    derived

    Network-security measures (link encryption, perimeter monitoring at ground stations, signal-protection treatment in mission planning) are the obligations under which the entity reduces uplink-intercept utility.

  • REC-0005.02Downlink InterceptST0001
    addresses
    moderate
    derived

    Network-security obligations cover the downlink processing chain at the entity's ground stations and require protection of telemetry pipelines from unauthorized observation.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.