CAPEC™ 523: Malicious Software Implanted
Description
An attacker implants malicious software into the system in the supply chain distribution channel, with purpose of causing malicious disruption or allowing for additional compromise when the system is deployed.
Source: CAPEC™ 523
Related ASVS Requirements
ASVS (5.0): 1.3.2, 10.4.7, 11.3.3, 11.4.3, 13.3.1, 13.3.2, 13.3.3, 13.4.2, 14.2.4, 15.1.1, 15.1.2, 15.1.4, 15.1.5, 15.2.1, 15.2.4, 15.2.5, 16.3.3, 16.3.4, 4.1.5, 5.1.1, 5.2.2, 5.3.1, 5.3.2, 5.4.1, 5.4.2, 5.4.3, 6.7.1