nis2-impl

Annex 3.6.2

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (7)

Techniques referencing this article

  • EX-0010.01RansomwareST0004
    addresses
    moderate
    derived

    Annex 3.6.2 requires post-incident reviews to feed back into the security approach; ransomware incidents typically expose backup, segmentation or auth weaknesses whose remediation closes the loop on Annex 3.5.1 response.

  • EX-0010.02Wiper MalwareST0004
    addresses
    moderate
    derived

    Post-incident review of a wiper event must contribute to improving the security approach — typically updating backup discipline, integrity-verification cadence and segmentation boundaries.

  • IMP-0001Deception (or Misdirection)ST0009
    addresses
    moderate
    derived

    Post-incident review must improve the security approach: deception events typically expose telemetry-validation gaps the entity must close.

  • IMP-0002DisruptionST0009
    addresses
    moderate
    derived

    Improvements driven by disruption post-incident reviews typically include continuity-plan updates, redundancy adjustments and detection refinements.

  • IMP-0003DenialST0009
    addresses
    moderate
    derived

    Improvements driven by denial post-incident review typically extend to backup-and-redundancy hardening and crisis-management procedure refinements.

  • IMP-0005DestructionST0009
    addresses
    moderate
    derived

    Improvements driven by destruction-event post-incident reviews typically span backup integrity, segmentation hardening and crisis-management procedure refinements.

  • RD-0002Compromise InfrastructureST0002
    addresses
    moderate
    derived

    Improvements from infrastructure-compromise post-incident review typically include hardening of compromised segments and detection-coverage extensions.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.