| 1 | Malicious software / code | — | Software, or part of software, that assists in unlawfully connecting to a network and information system, taking it over and controlling it, disrupting or altering its operation, destroying, damaging, deleting or altering digital data, removing or restricting the ability to use it, or unlawfully appropriating non-public digital data. |
| 1.1 | Malicious software / code | Advanced persistent threat (APT) | Advanced malicious software. |
| 1.2 | Malicious software / code | Wiper / ransomware | Program code that encrypts or destroys the data of the network and information system, or demands a ransom. |
| 1.3 | Malicious software / code | Intruder-controlled system components | Parts of the network and information system that are actively controlled by intruders. |
| 1.4 | Malicious software / code | Malware distribution | Distribution of malicious software. |
| 2 | Information gathering | — | Reconnaissance or other suspicious activity aimed at observing and collecting information, discovering weak points, and carrying out threatening actions. |
| 3 | Intrusion attempts | — | An attempt to intrude, or to disrupt the operation of the network and information system, by exploiting known vulnerabilities or by guessing passwords (brute force). |
| 3.1 | Intrusion attempts | Zero-day exploitation | One or more previously unknown vulnerabilities are exploited. |
| 3.2 | Intrusion attempts | Reconnaissance or other malicious activity | Reconnaissance of the network and information system or other malicious activity — port scanning, password guessing, malware distribution and similar. |
| 3.3 | Intrusion attempts | Known vulnerability exploitation | Known and publicly published vulnerabilities are exploited. |
| 4 | Intrusions | — | A successful intrusion and/or unauthorised use of the network and information system, of application software, or of a service. |
| 4.1 | Intrusions | Actions against the system or its security measures | Actions against the system or its security measures; appropriation of information; destruction; damage that disrupts uninterrupted service provision, affects the reliability of processed information, distorts content, or reduces user trust. |
| 4.2 | Intrusions | Unauthorised access obtained | Unauthorised access is obtained to the network and information system, to application software, or to a service. |
| 5 | Service disruption, availability breaches | — | Actions that disrupt the operation of the network and information system or the services provided (DoS, DDoS); damage to the system or a part of it that disrupts the system and/or its services. |
| 5.1 | Service disruption, availability breaches | Interruption or downtime breach | Interruption of the services provided, or exceeding of the maximum permissible service downtime. |
| 5.2 | Service disruption, availability breaches | Degradation of continuous provision | Disruption of uninterrupted service provision that may affect the availability of processed information and/or of the services provided. |
| 6 | Supply chain attacks | — | The infrastructure of third parties providing services to the manager and/or processor of the network and information system is exploited in order to gain or exert influence over the service recipient's infrastructure. |