Annex 3.6.2
Mapped SPARTA techniques (7)
Techniques referencing this article
Annex 3.6.2 requires post-incident reviews to feed back into the security approach; ransomware incidents typically expose backup, segmentation or auth weaknesses whose remediation closes the loop on Annex 3.5.1 response.
Post-incident review of a wiper event must contribute to improving the security approach — typically updating backup discipline, integrity-verification cadence and segmentation boundaries.
Post-incident review must improve the security approach: deception events typically expose telemetry-validation gaps the entity must close.
Improvements driven by disruption post-incident reviews typically include continuity-plan updates, redundancy adjustments and detection refinements.
Improvements driven by denial post-incident review typically extend to backup-and-redundancy hardening and crisis-management procedure refinements.
Improvements driven by destruction-event post-incident reviews typically span backup integrity, segmentation hardening and crisis-management procedure refinements.
Improvements from infrastructure-compromise post-incident review typically include hardening of compromised segments and detection-coverage extensions.