All techniques
REC-0008
ST0001Reconnaissance

Gather Supply Chain Information

Description

Threat actors map the end-to-end pathway by which hardware, software, data, and people move from design through AIT, launch, and on-orbit sustainment. They catalog manufacturers and lots, test and calibration houses, logistics routes and waypoints, integrator touchpoints, key certificates and tooling, update and key-loading procedures, and who holds custody at each handoff. They correlate this with procurement artifacts, SBOMs, BOMs, and service contracts to locate where trust is assumed rather than verified. Particular attention falls on exceptions, engineering builds, rework tickets, advance replacements, depot repairs, and urgent field updates, because controls are frequently relaxed there. The result is a prioritized list of choke points (board fabrication, FPGA bitstream signing, image repositories, CI/CD runners, cloud artifact stores, freight forwarders) where compromise yields outsized effect.

Mappings

EU regulation articles

  • craAnnex I, Part II, (1)
    addresses
    moderate
    derived

    Manufacturer obligation to identify and document components (SBOM) is what makes supply-chain visibility complete on the manufacturer side; reconnaissance against the same chain produces a less-asymmetric picture when the manufacturer maintains its own component inventory.

  • craAnnex I, Part II, (5)
    relates to
    high
    direct

    Information-gathering on supply chain (primary mappings: Part II, (1) + Art. 13(5)) presupposes a CVD policy under (5) to coordinate inbound reports about supply-chain weaknesses.

  • craArt. 13(5)
    addresses
    moderate
    direct

    Manufacturer obligation to exercise due diligence when integrating components sourced from third parties is the upstream discipline that constrains supply-chain reconnaissance: a manufacturer with documented due-diligence cannot be surprised by what its supply-chain map reveals to an adversary.

  • eu-space-actArt. 92(1)
    addresses
    high
    direct

    Supply-chain reconnaissance is the canonical case 92(1)'s supply-chain risk management framework addresses — operators must structure contracts to limit the value of supply-chain mapping.

  • eu-space-actArt. 92(2)
    addresses
    high
    direct

    92(2)'s strategy-to-reduce-risks-in-the-supply-chain obligation (with measures from Annex VII point 6) is directly aimed at the supply-chain attack surface that REC-0008 enumerates.

  • eu-space-actArt. 92(3)
    addresses
    moderate
    direct

    92(3)'s inventory of critical assets of non-Union origin captures the supply-chain dependency landscape that adversaries reconstruct via reconnaissance; the inventory is the operator-side counterpart to adversary mapping.

  • nis2Art. 21(2)(d)
    addresses
    high
    direct

    End-to-end supplier mapping (manufacturers, integrators, calibration houses, logistics, depot repairs, key-loading) is the very asset class Art. 21(2)(d)'s supplier-relationship security obligation governs, including the security-related aspects of those relationships.

  • nis2Art. 21(2)(i)
    addresses
    moderate
    direct

    Procurement artefacts, SBOMs/BOMs, key certificates, and service contracts are access-controlled assets; Art. 21(2)(i) is the obligation that constrains who can compile or extract the choke-point map an adversary would otherwise harvest.

  • nis2Art. 21(3)
    addresses
    high
    direct

    The technique highlights waiver-driven and depot-relaxed control points; supplier-specific vulnerability assessment and consideration of the overall quality of supplier cybersecurity practices under Art. 21(3) is the obligation that requires those weak points be triaged.

  • nis2-implAnnex 12.2.1
    addresses
    moderate
    derived

    Handling-of-assets policy applies to supplier directories, contract registers and AIT records — the exact artefacts a supply-chain recon adversary harvests.

  • nis2-implAnnex 5.1.1
    addresses
    high
    derived

    Supply-chain reconnaissance maps the same end-to-end pathway the implementing regulation requires the entity to govern with a formal supply-chain security policy; that policy's confidentiality discipline is what prevents the adversary's pathway map from being assembled.

  • nis2-implAnnex 5.1.7
    addresses
    moderate
    derived

    Continuous monitoring of supplier conduct and contractual provisions is the procedural lever that controls how supply-chain information is distributed and protected, including from third-party leakage.

ENISA controls

  • An asset inventory that includes assets provided or managed by third parties is the operator-side picture corresponding to REC-0008's adversary view.

  • Supplier security management is the umbrella supply-chain control that governs whose disclosures REC-0008 can mine.

  • SBOM generation is the principal artefact through which supply-chain composition is exposed; controlling its access dictates REC-0008 yield.

  • Software supply chain integrity controls regulate the integrity and visibility of the supplier ecosystem REC-0008 attempts to enumerate.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, REC-0008 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.