nis2-impl

Annex 6.9.1

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (12)

Techniques referencing this article

  • DE-0002.01Inhibit Ground System FunctionalityST0006
    addresses
    moderate
    derived

    Where ground-system inhibition rides through malicious software (telemetry-display tampering, processing-pipeline subversion), the malware-protection obligation applies as the detective and preventive layer.

  • DE-0007Evasion via RootkitST0006
    addresses
    high
    derived

    Rootkit-based evasion is malicious software interposing on reporting paths; the malware-protection obligation requires detection-or-prevention measures appropriate to the asset.

  • DE-0008Evasion via BootkitST0006
    addresses
    high
    derived

    Bootkit evasion is malicious software running before higher-layer integrity checks; the malware-protection obligation extends to the boot chain through pre-boot integrity verification and measured-boot mechanisms.

  • Geofenced trigger logic embedded in flight code is malicious and unauthorized software; protection-against-malicious-and-unauthorized-software obligations require detection and prevention measures appropriate to the asset.

  • EX-0008Time Synchronized ExecutionST0004
    addresses
    moderate
    derived

    Time-synchronized triggers are dormant malicious logic; protection-against-malicious-and-unauthorized-software obligations cover detection of code that activates on time-of-day or elapsed-time conditions.

  • EX-0008.01Absolute Time SequencesST0004
    addresses
    moderate
    derived

    Code that watches a wall-clock time source for activation is unauthorized software; the malware-protection obligations cover detection-or-prevention measures appropriate to the asset.

  • EX-0008.02Relative Time SequencesST0004
    addresses
    moderate
    derived

    Code that latches to elapsed-time or event-relative triggers is unauthorized software; the malware-protection obligations cover this dormant-trigger class.

  • EX-0010Malicious CodeST0004
    addresses
    high
    direct

    Introduction of executable logic (binaries, scripts, shellcode, interpreted data payloads) onto flight or ground systems is the canonical malicious-and-unauthorized-software threat the implementing regulation requires the entity to detect or prevent.

  • EX-0010.01RansomwareST0004
    addresses
    high
    derived

    Ransomware is malicious software encrypting data and configuration; the malware-protection obligations require the entity to implement detection or prevention measures appropriate to the asset.

  • EX-0010.02Wiper MalwareST0004
    addresses
    high
    derived

    Wiper malware is the canonical destructive-software class the malware-protection obligations are designed to counter through detection and prevention.

  • EX-0010.03RootkitST0004
    addresses
    high
    derived

    A rootkit is malicious software that interposes on system-state reporting; the malware-protection obligations require the entity to implement detection or prevention measures appropriate to the asset.

  • EX-0010.04BootkitST0004
    addresses
    high
    derived

    A bootkit is malicious software seizing the pre-OS boot chain; the malware-protection obligation requires detection-or-prevention measures appropriate to the boot-chain asset.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.