nis2-impl

Annex 3.6.1

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (7)

Techniques referencing this article

  • EX-0010.01RansomwareST0004
    addresses
    high
    derived

    Annex 3.6.1 requires post-incident review after recovery; ransomware events are exactly the high-impact class for which root-cause review and lessons-learned analysis must follow Annex 3.5.1 incident response.

  • EX-0010.02Wiper MalwareST0004
    addresses
    moderate
    derived

    Wiper events are the canonical class for which post-incident review is essential — the review identifies how destructive code reached production and how backup integrity held under attack.

  • IMP-0001Deception (or Misdirection)ST0009
    addresses
    moderate
    derived

    Post-incident review is essential for deception events because the entity must reconstruct which downstream decisions were made on falsified evidence and remediate accordingly.

  • IMP-0002DisruptionST0009
    addresses
    moderate
    derived

    Post-incident review of disruption events identifies the failure modes (link saturation, parser overload, partial responder availability) that allowed the event.

  • IMP-0003DenialST0009
    addresses
    moderate
    derived

    Post-incident reviews of denial events identify whether redundancy, fail-over or load-shedding designs proved adequate, and what must change.

  • IMP-0005DestructionST0009
    addresses
    moderate
    derived

    Post-incident review of destruction events is the highest-priority class — identifying root cause and propagation path is essential for cross-mission lessons learned.

  • RD-0002Compromise InfrastructureST0002
    addresses
    moderate
    derived

    Post-incident review of infrastructure-compromise events identifies which segments allowed adversary staging and remediation gaps.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.