Annex 3.4.2
Mapped SPARTA techniques (7)
Techniques referencing this article
Annex 3.4.2 specifies how assessment is performed (impact-based criteria, severity assignment); for ransomware events, this is the procedure that converts a 'suspicious encryption activity' alert into the incident classification that drives Annex 3.5.1 response.
Annex 3.4.2 operational assessment criteria apply to wiper events: scope of destruction, affected subsystems, and recovery feasibility drive the incident classification feeding 3.5.1.
Operational assessment for deception relies on cross-source telemetry consistency checks and severity assignment based on downstream wrong-decision exposure.
Operational assessment criteria for disruption (downtime, affected services, cross-customer impact) feed directly into Annex 3.5.1 response activation.
Operational assessment for denial events (resource exhaustion, communications blocking) drives Annex 3.5.1 incident-response activation and recovery prioritization.
Operational assessment for destruction events evaluates whether mission services are recoverable from backups or whether crisis-management activation is required.
Operational assessment for infrastructure-compromise events evaluates dwell time, scope and lateral-movement potential to drive Annex 3.5.1 response.