Art. 23(4)
Mapped SPARTA techniques (18)
Techniques referencing this article
Primary mapping to Art. 23(1) triggers the Art. 23(4) timing cascade (24-hour early warning, 72-hour incident notification, one-month final report). For a ransomware event the deadlines are operationally tight but unconditional.
Primary mapping to Art. 23(1) triggers Art. 23(4) deadlines. Wiper events are time-critical and typically detected after data is already destroyed, so the 24-hour early warning often lands first with limited information.
Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. For flooding, the 24-hour early warning is the first reporting milestone since the attack is observable in real time but its scope and persistence are not.
Primary mapping to Art. 23(1) drives the Art. 23(4) deadlines. MOC compromise typically has delayed detection, so the 24-hour early-warning clock starts at the awareness moment, not at the intrusion moment.
Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Partner-site compromise is often detected via the partner's disclosure to the operator, which sets the awareness moment for the 24-hour clock.
Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. The 24-hour early warning starts at awareness, often delayed for stealthy GS intrusions.
Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Malicious-commanding events are often visible in command-history audits; awareness can lag the action by minutes to days.
Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Deception is often detected only after downstream wrong decisions surface, so awareness lags the deception window.
Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Disruption is usually directly observable, so the 24-hour early warning starts at the disruption moment.
Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Denial is typically observable immediately; the 24-hour early warning starts at detection.
Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Degradation has slow-onset signatures; the 24-hour clock starts at confirmation that degradation is adversarial rather than nominal.
Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Destruction is typically observable near-instantly via lost telemetry; the 24-hour clock starts at confirmation.
Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Theft is often detected via downstream IOC matches; awareness can lag exfil by significant time.
Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Constellation hopping is detected via cross-satellite anomaly correlation, often days after first-asset compromise.
Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Persistent presence is usually discovered via threat-hunting or post-incident review; awareness lags initial implant.
Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Infrastructure-compromise detection often surfaces via egress anomalies; awareness can lag the compromise window.
Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Awareness typically lags GS compromise by days to weeks.
Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Awareness typically arrives via the third-party provider's own disclosure to the operator.