Annex 6.9.1
Mapped SPARTA techniques (12)
Techniques referencing this article
Where ground-system inhibition rides through malicious software (telemetry-display tampering, processing-pipeline subversion), the malware-protection obligation applies as the detective and preventive layer.
Rootkit-based evasion is malicious software interposing on reporting paths; the malware-protection obligation requires detection-or-prevention measures appropriate to the asset.
Bootkit evasion is malicious software running before higher-layer integrity checks; the malware-protection obligation extends to the boot chain through pre-boot integrity verification and measured-boot mechanisms.
Geofenced trigger logic embedded in flight code is malicious and unauthorized software; protection-against-malicious-and-unauthorized-software obligations require detection and prevention measures appropriate to the asset.
Time-synchronized triggers are dormant malicious logic; protection-against-malicious-and-unauthorized-software obligations cover detection of code that activates on time-of-day or elapsed-time conditions.
Code that watches a wall-clock time source for activation is unauthorized software; the malware-protection obligations cover detection-or-prevention measures appropriate to the asset.
Code that latches to elapsed-time or event-relative triggers is unauthorized software; the malware-protection obligations cover this dormant-trigger class.
Introduction of executable logic (binaries, scripts, shellcode, interpreted data payloads) onto flight or ground systems is the canonical malicious-and-unauthorized-software threat the implementing regulation requires the entity to detect or prevent.
Ransomware is malicious software encrypting data and configuration; the malware-protection obligations require the entity to implement detection or prevention measures appropriate to the asset.
Wiper malware is the canonical destructive-software class the malware-protection obligations are designed to counter through detection and prevention.
A rootkit is malicious software that interposes on system-state reporting; the malware-protection obligations require the entity to implement detection or prevention measures appropriate to the asset.
A bootkit is malicious software seizing the pre-OS boot chain; the malware-protection obligation requires detection-or-prevention measures appropriate to the boot-chain asset.