Annex 3.6.1
Mapped SPARTA techniques (7)
Techniques referencing this article
Annex 3.6.1 requires post-incident review after recovery; ransomware events are exactly the high-impact class for which root-cause review and lessons-learned analysis must follow Annex 3.5.1 incident response.
Wiper events are the canonical class for which post-incident review is essential — the review identifies how destructive code reached production and how backup integrity held under attack.
Post-incident review is essential for deception events because the entity must reconstruct which downstream decisions were made on falsified evidence and remediate accordingly.
Post-incident review of disruption events identifies the failure modes (link saturation, parser overload, partial responder availability) that allowed the event.
Post-incident reviews of denial events identify whether redundancy, fail-over or load-shedding designs proved adequate, and what must change.
Post-incident review of destruction events is the highest-priority class — identifying root cause and propagation path is essential for cross-mission lessons learned.
Post-incident review of infrastructure-compromise events identifies which segments allowed adversary staging and remediation gaps.