nis2-impl

Annex 3.6.3

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (7)

Techniques referencing this article

  • EX-0010.01RansomwareST0004
    addresses
    moderate
    derived

    Annex 3.6.3 requires planned-interval review of whether incidents triggered post-incident reviews; a ransomware event would be expected to populate that schedule.

  • EX-0010.02Wiper MalwareST0004
    addresses
    moderate
    derived

    Planned-interval review under Annex 3.6.3 must include wiper events in the population whose post-incident-review status is tracked.

  • IMP-0001Deception (or Misdirection)ST0009
    addresses
    moderate
    derived

    Planned-interval review tracks whether deception events are captured by the post-incident-review process.

  • IMP-0002DisruptionST0009
    addresses
    moderate
    derived

    Planned-interval Annex 3.6.3 review tracks whether disruption events are captured by post-incident-review discipline.

  • IMP-0003DenialST0009
    addresses
    moderate
    derived

    Annex 3.6.3 planned-interval review of post-incident-review status applies to denial events.

  • IMP-0005DestructionST0009
    addresses
    moderate
    derived

    Annex 3.6.3 planned-interval tracking ensures destruction events do not slip the post-incident-review schedule.

  • RD-0002Compromise InfrastructureST0002
    addresses
    moderate
    derived

    Annex 3.6.3 planned-interval tracking applies to infrastructure-compromise events.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.