nis2-impl

Annex 3.4.2

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (7)

Techniques referencing this article

  • EX-0010.01RansomwareST0004
    addresses
    moderate
    derived

    Annex 3.4.2 specifies how assessment is performed (impact-based criteria, severity assignment); for ransomware events, this is the procedure that converts a 'suspicious encryption activity' alert into the incident classification that drives Annex 3.5.1 response.

  • EX-0010.02Wiper MalwareST0004
    addresses
    moderate
    derived

    Annex 3.4.2 operational assessment criteria apply to wiper events: scope of destruction, affected subsystems, and recovery feasibility drive the incident classification feeding 3.5.1.

  • IMP-0001Deception (or Misdirection)ST0009
    addresses
    high
    derived

    Operational assessment for deception relies on cross-source telemetry consistency checks and severity assignment based on downstream wrong-decision exposure.

  • IMP-0002DisruptionST0009
    addresses
    moderate
    derived

    Operational assessment criteria for disruption (downtime, affected services, cross-customer impact) feed directly into Annex 3.5.1 response activation.

  • IMP-0003DenialST0009
    addresses
    moderate
    derived

    Operational assessment for denial events (resource exhaustion, communications blocking) drives Annex 3.5.1 incident-response activation and recovery prioritization.

  • IMP-0005DestructionST0009
    addresses
    moderate
    derived

    Operational assessment for destruction events evaluates whether mission services are recoverable from backups or whether crisis-management activation is required.

  • RD-0002Compromise InfrastructureST0002
    addresses
    moderate
    derived

    Operational assessment for infrastructure-compromise events evaluates dwell time, scope and lateral-movement potential to drive Annex 3.5.1 response.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.