nis2-impl

Annex 3.4.1

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (7)

Techniques referencing this article

  • EX-0010.01RansomwareST0004
    addresses
    high
    derived

    Primary mapping to Annex 3.5.1 (incident response) implies upstream event assessment and classification. Annex 3.4.1 requires the entity to determine whether suspicious events constitute incidents and assign severity — the gate that must run before ransomware-class incident-response procedures activate.

  • EX-0010.02Wiper MalwareST0004
    addresses
    moderate
    derived

    Wiper events require immediate assessment to classify scope (data destroyed, executable images affected) and severity before Annex 3.5.1 response activates.

  • IMP-0001Deception (or Misdirection)ST0009
    addresses
    moderate
    derived

    Deception requires careful assessment to distinguish manipulated telemetry from genuine anomalies; Annex 3.4.1 is the assessment gate that must classify events before Annex 3.5.1 response activates.

  • IMP-0002DisruptionST0009
    addresses
    moderate
    derived

    Disruption events trigger the assessment gate before Annex 3.5.1 response — scope, expected duration and recoverability are classified per Annex 3.4.1.

  • IMP-0003DenialST0009
    addresses
    moderate
    derived

    Denial events trigger Annex 3.4.1 assessment before Annex 3.5.1 response — identifying scope and resource exhaustion vector is the assessment-gate output.

  • IMP-0005DestructionST0009
    addresses
    moderate
    derived

    Destruction events require the most stringent assessment under Annex 3.4.1 — scope, recoverability and crisis-management activation thresholds drive Annex 3.5.1 response.

  • RD-0002Compromise InfrastructureST0002
    addresses
    high
    derived

    Compromise of the entity's infrastructure (used as adversary staging) requires Annex 3.4.1 assessment to determine whether observed activity constitutes an incident before Annex 3.5.1 response activates.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.