nis2

Art. 23(4)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (18)

Techniques referencing this article

  • EX-0010.01RansomwareST0004
    addresses
    moderate
    derived

    Primary mapping to Art. 23(1) triggers the Art. 23(4) timing cascade (24-hour early warning, 72-hour incident notification, one-month final report). For a ransomware event the deadlines are operationally tight but unconditional.

  • EX-0010.02Wiper MalwareST0004
    addresses
    moderate
    derived

    Primary mapping to Art. 23(1) triggers Art. 23(4) deadlines. Wiper events are time-critical and typically detected after data is already destroyed, so the 24-hour early warning often lands first with limited information.

  • EX-0013FloodingST0004
    addresses
    high
    derived

    Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. For flooding, the 24-hour early warning is the first reporting milestone since the attack is observable in real time but its scope and persistence are not.

  • EXF-0007Compromised Ground SystemST0008
    addresses
    high
    derived

    Primary mapping to Art. 23(1) drives the Art. 23(4) deadlines. MOC compromise typically has delayed detection, so the 24-hour early-warning clock starts at the awareness moment, not at the intrusion moment.

  • EXF-0009Compromised Partner SiteST0008
    addresses
    high
    derived

    Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Partner-site compromise is often detected via the partner's disclosure to the operator, which sets the awareness moment for the 24-hour clock.

  • IA-0007Compromise Ground SystemST0003
    addresses
    high
    derived

    Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. The 24-hour early warning starts at awareness, often delayed for stealthy GS intrusions.

  • IA-0007.02Malicious Commanding via Valid GSST0003
    addresses
    moderate
    derived

    Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Malicious-commanding events are often visible in command-history audits; awareness can lag the action by minutes to days.

  • IMP-0001Deception (or Misdirection)ST0009
    addresses
    moderate
    derived

    Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Deception is often detected only after downstream wrong decisions surface, so awareness lags the deception window.

  • IMP-0002DisruptionST0009
    addresses
    moderate
    derived

    Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Disruption is usually directly observable, so the 24-hour early warning starts at the disruption moment.

  • IMP-0003DenialST0009
    addresses
    high
    derived

    Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Denial is typically observable immediately; the 24-hour early warning starts at detection.

  • IMP-0004DegradationST0009
    addresses
    moderate
    derived

    Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Degradation has slow-onset signatures; the 24-hour clock starts at confirmation that degradation is adversarial rather than nominal.

  • IMP-0005DestructionST0009
    addresses
    high
    derived

    Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Destruction is typically observable near-instantly via lost telemetry; the 24-hour clock starts at confirmation.

  • IMP-0006TheftST0009
    addresses
    high
    derived

    Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Theft is often detected via downstream IOC matches; awareness can lag exfil by significant time.

  • LM-0003Constellation Hopping via CrosslinkST0007
    addresses
    moderate
    derived

    Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Constellation hopping is detected via cross-satellite anomaly correlation, often days after first-asset compromise.

  • PER-0003Ground System PresenceST0005
    addresses
    moderate
    derived

    Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Persistent presence is usually discovered via threat-hunting or post-incident review; awareness lags initial implant.

  • RD-0002Compromise InfrastructureST0002
    addresses
    high
    derived

    Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Infrastructure-compromise detection often surfaces via egress anomalies; awareness can lag the compromise window.

  • RD-0002.01Mission-Operated Ground SystemST0002
    addresses
    moderate
    derived

    Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Awareness typically lags GS compromise by days to weeks.

  • RD-0002.023rd Party Ground SystemST0002
    addresses
    moderate
    derived

    Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Awareness typically arrives via the third-party provider's own disclosure to the operator.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.