nis2

Art. 21(2)(j)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (22)

Techniques referencing this article

  • DE-0004MasqueradingST0006
    addresses
    moderate
    direct

    MFA/continuous authentication on operator tools and mission consoles under Art. 21(2)(j) defeats insider-credential masquerading at the ground-side end of the chain.

  • DE-0011Credentialed EvasionST0006
    mitigates
    high
    direct

    Multi-factor authentication or continuous authentication under Art. 21(2)(j) limits the value of valid-but-stolen credentials and forces session-binding signals that distinguish legitimate from credentialed-evasive use.

  • EXF-0007Compromised Ground SystemST0008
    mitigates
    moderate
    direct

    Mass-scale exfiltration via mission-control servers, modem chains, and archive databases depends on attacker credentials evading detection on operator/admin accounts; multi-factor or continuous authentication under Art. 21(2)(j) directly closes that gap.

  • EXF-0008Compromised Developer SiteST0008
    addresses
    moderate
    direct

    Multi-factor authentication on developer-site identity providers, source-control accounts, and CI/CD orchestrators under Art. 21(2)(j) reduces the credential-driven entry path to the development environment the technique exploits.

  • EXF-0009Compromised Partner SiteST0008
    addresses
    moderate
    inferred

    Art. 21(2)(j) (MFA/secured comms within the entity) is domain-relevant to third-party access exposure but does not interdict this vector: mirroring mission data and MITM of partner-to-MOC links bypass any authenticated entity session. The operative control is secured-comms encryption of cross-org links, not MFA.

  • IA-0004.01Ground StationST0003
    mitigates
    moderate
    direct

    Multi-factor authentication on backup-station operator accounts and scheduler portals under Art. 21(2)(j) blocks the credential path through which adversaries establish presence on the standby ground segment ahead of failover.

  • IA-0007Compromise Ground SystemST0003
    addresses
    moderate
    direct

    Multi-factor authentication or continuous authentication under Art. 21(2)(j) defeats the credential-driven path through which most ground-segment compromises start (phishing, vendor-account theft, lateral IT-to-ops).

  • IA-0007.02Malicious Commanding via Valid GSST0003
    addresses
    moderate
    direct

    Continuous authentication or step-up MFA on operator sessions under Art. 21(2)(j) raises the bar against an attacker reusing a legitimate ground-segment session to insert procedures across multiple passes.

  • IA-0008Rogue External EntityST0003
    addresses
    moderate
    inferred

    Scoped to its cyber authentication-defeat core, IA-0008 (a rogue external entity presenting mission-compatible traffic) triggers NIS2 Art. 21(2)(j): correct authentication of mission traffic rejects an origin that lacks valid credentials. The clearly physical strands of the technique (RF-geometry exploitation, directed-energy, and kinetic counterspace effects) fall outside the Article 21(2) cyber-risk measures and are excluded from this mapping. The jamming and spoofing electronic-warfare strand is not decided here; it is deferred to the E/F counterspace-scope determination, consistent with the IA-0008.03 hold.

  • IA-0008.02Rogue SpacecraftST0003
    addresses
    moderate
    inferred

    IA-0008.02 succeeds when an impostor (rogue) spacecraft is honored on the inter-satellite link without valid credentials. NIS2 Art. 21(2)(j) governs the risk: correct authentication of the inter-satellite link rejects a peer presenting mission-compatible crosslink traffic but lacking valid keys. Orbital-geometry-aware anomaly detection is a compensating backstop, not the primary obligation.

  • IA-0009Trusted RelationshipST0003
    mitigates
    moderate
    direct

    Multi-factor authentication on partner integration accounts, jump hosts, and federated identities under Art. 21(2)(j) limits the value of credentials harvested from a compromised counterpart.

  • MFA on federated credentials and collaboration-portal accounts under Art. 21(2)(j) limits the value of any single compromised partner identity feeding configuration tables or commanding tools.

  • IA-0009.02VendorST0003
    addresses
    moderate
    direct

    MFA on vendor remote-admin accounts, signing-tool sessions, and cross-account cloud roles under Art. 21(2)(j) reduces the credential-driven escalation path from vendor enterprise to mission infrastructure.

  • LM-0007Credentialed TraversalST0007
    mitigates
    high
    direct

    Continuous authentication and step-up MFA at enclave boundaries under Art. 21(2)(j) limit a single credential's reach by re-authenticating on cross-domain traversal — precisely the boundaries this technique abuses.

  • PER-0003Ground System PresenceST0005
    addresses
    moderate
    direct

    Continuous authentication and step-up MFA on operator/admin sessions under Art. 21(2)(j) are what limit a persistent attacker's ability to refresh tooling, queue commands across passes, and mirror legitimate operator behaviour.

  • PER-0005Credentialed PersistenceST0005
    mitigates
    moderate
    direct

    Multi-factor authentication or continuous authentication under Art. 21(2)(j) defeats the 'operating with legitimate credentials' premise the technique relies on — even valid credentials become single-use without a second factor or session-binding signal.

  • Multi-factor authentication on customer accounts at commercial GS providers under Art. 21(2)(j) defeats the credential-purchase or weak-vetting routes through which adversaries co-opt legitimate scheduling and front-end configuration.

  • RD-0002Compromise InfrastructureST0002
    addresses
    high
    direct

    Multi-factor authentication or continuous authentication under Art. 21(2)(j) directly defeats the stolen-credential, exposed-remote-support, and lateral-IT-to-ops paths that drive most infrastructure compromise.

  • RD-0002.01Mission-Operated Ground SystemST0002
    mitigates
    moderate
    direct

    MFA on operator and admin accounts under Art. 21(2)(j) defeats the dominant phishing-and-pivot path through which mission-operated ground systems are compromised.

  • RD-0002.023rd Party Ground SystemST0002
    addresses
    moderate
    direct

    MFA on customer accounts at the third-party provider under Art. 21(2)(j) blocks the credential-driven misuse path the technique relies on for scheduling, front-end configuration, and data egress.

  • REC-0003.04Valid CredentialsST0001
    mitigates
    high
    direct

    Multi-factor authentication or continuous authentication under Art. 21(2)(j) directly defeats reuse of credentials harvested from phishing, supply-chain compromise, repos, dumps, contractor laptops, or sanitised training data.

  • REC-0006.01Development EnvironmentST0001
    addresses
    moderate
    inferred

    addresses; Art. 21(2)(j) is domain-relevant because developer-site IdPs, source-control, and CI/CD accounts should use MFA, but MFA does not interdict passive enumeration of the build environment, repo layouts, or secrets-in-configs; the operative control is the secure-development assurance of Art. 21(2)(e).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.