nis2-impl

Annex 4.2.1

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (4)

Techniques referencing this article

  • EX-0010.01RansomwareST0004
    addresses
    high
    direct

    Backup-and-redundancy obligations require the entity to maintain backup copies of data and resources so that ransomware-induced loss of access does not become loss of operations; backups are the recovery lever specifically targeted at this attack class.

  • EX-0010.02Wiper MalwareST0004
    addresses
    high
    derived

    Backup obligations are the principal recovery lever for wiper events; without backups the destruction is final, with them the entity can restore mission-critical data and configuration.

  • IMP-0003DenialST0009
    addresses
    high
    derived

    Backup-and-redundancy obligations require sufficient available resources, including facilities, to restore service after denial events; redundancy is the procedural lever that converts denial from outage into degraded-but-available operation.

  • IMP-0005DestructionST0009
    addresses
    high
    derived

    Backup-and-redundancy obligations are the principal recovery lever for destruction events affecting data, commands or subsystem state; backups are the difference between recoverable destruction and total loss.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.