nis2-impl

Annex 3.3.1

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (13)

Techniques referencing this article

  • DE-0001Disable Fault ManagementST0006
    addresses
    moderate
    derived

    Operators are positioned to notice missing safing events and suppressed FDIR alerts; Annex 3.3.1 mechanism captures those operator escalations as the upstream feeder for the Annex 3.2.1 monitoring pipeline.

  • DE-0002Disrupt or Deceive DownlinkST0006
    addresses
    moderate
    derived

    Downlink-disruption is operator-visible (telemetry pipelines empty, displays freeze, alerts queue); Annex 3.3.1 mechanism captures rapid operator reports that complement automated link-margin alerts.

  • DE-0011Credentialed EvasionST0006
    addresses
    moderate
    derived

    Credentialed-evasion-class behaviour (off-hours activity by valid users, geographic anomalies, command-pattern deviations) is most reliably surfaced by colleagues noticing irregularities; Annex 3.3.1 mechanism is the upstream feeder for the Annex 3.2.1 monitoring this technique's primary mapping invokes.

  • EX-0010.01RansomwareST0004
    addresses
    moderate
    derived

    Ransomware events are operator-visible (mission impact, encrypted files, denied access); Annex 3.3.1 requires a simple mechanism for employees to report suspicious events, which is the upstream feeder for the 3.4 assessment that classifies the event and triggers 3.5.1 response.

  • EX-0010.02Wiper MalwareST0004
    addresses
    moderate
    derived

    Wiper events leave operator-visible aftermath; Annex 3.3.1 mechanism is the upstream feeder that surfaces such suspicious events to assessment and incident-response procedures.

  • EXF-0007Compromised Ground SystemST0008
    addresses
    moderate
    derived

    Compromised-ground-system exfiltration produces operator-visible signals (anomalous workstation behaviour, unexpected exports). Annex 3.3.1 mechanism captures employee escalation that complements automated egress monitoring; the technique's primary mapping to Annex 3.2.1 monitoring depends on those upstream human signals to separate routine from suspicious activity.

  • IA-0007Compromise Ground SystemST0003
    addresses
    moderate
    derived

    Ground-system intrusion produces operator-visible anomalies (unfamiliar logins, unexpected admin actions, screen-recorder behaviour); Annex 3.3.1 mechanism is the upstream feeder for the Annex 3.2.1 monitoring this technique already triggers.

  • IA-0007.02Malicious Commanding via Valid GSST0003
    addresses
    moderate
    derived

    Malicious commanding via valid GS produces command-history anomalies operators are positioned to spot; Annex 3.3.1 mechanism captures those reports and feeds the Annex 3.2.1 monitoring pipeline this technique's primary mapping invokes.

  • IMP-0001Deception (or Misdirection)ST0009
    addresses
    moderate
    derived

    Operators are often the first to notice deception (telemetry that does not match expected behaviour); Annex 3.3.1 ensures they have a mechanism to escalate without friction, feeding 3.4 assessment.

  • IMP-0002DisruptionST0009
    addresses
    moderate
    derived

    Disruption is operator-visible; Annex 3.3.1 mechanism enables rapid employee escalation that feeds 3.4 assessment ahead of automated detection.

  • IMP-0003DenialST0009
    addresses
    moderate
    derived

    Denial is observable through operator-noticed loss of access; Annex 3.3.1 mechanism captures employee-side denial reports that complement automated link-margin detection.

  • IMP-0005DestructionST0009
    addresses
    moderate
    derived

    Destruction is operator-visible (lost telemetry, missing assets); Annex 3.3.1 mechanism captures rapid employee escalation that feeds 3.4 assessment ahead of mission-impact analysis.

  • PER-0003Ground System PresenceST0005
    addresses
    moderate
    derived

    Persistent ground-system presence produces analyst-visible anomalies (off-hours activity, account-usage drift, unexpected service-account behaviour); Annex 3.3.1 mechanism captures those analyst reports as the upstream feeder for the Annex 3.2.1 monitoring already in place.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.