Annex 3.4.1
Mapped SPARTA techniques (7)
Techniques referencing this article
Primary mapping to Annex 3.5.1 (incident response) implies upstream event assessment and classification. Annex 3.4.1 requires the entity to determine whether suspicious events constitute incidents and assign severity — the gate that must run before ransomware-class incident-response procedures activate.
Wiper events require immediate assessment to classify scope (data destroyed, executable images affected) and severity before Annex 3.5.1 response activates.
Deception requires careful assessment to distinguish manipulated telemetry from genuine anomalies; Annex 3.4.1 is the assessment gate that must classify events before Annex 3.5.1 response activates.
Disruption events trigger the assessment gate before Annex 3.5.1 response — scope, expected duration and recoverability are classified per Annex 3.4.1.
Denial events trigger Annex 3.4.1 assessment before Annex 3.5.1 response — identifying scope and resource exhaustion vector is the assessment-gate output.
Destruction events require the most stringent assessment under Annex 3.4.1 — scope, recoverability and crisis-management activation thresholds drive Annex 3.5.1 response.
Compromise of the entity's infrastructure (used as adversary staging) requires Annex 3.4.1 assessment to determine whether observed activity constitutes an incident before Annex 3.5.1 response activates.