Skip to content

DETECT (DE)

Possible cybersecurity attacks and compromises are found and analyzed

Informative References

  • CRI Profile v2.0: DE
  • CSF v1.1: DE
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 8.16
  • SCF: THR-01
  • SCF: THR-03
  • SCF: THR-07

Continuous Monitoring (DE.CM)

Assets are monitored to find anomalies, indicators of compromise, and other potentially adverse events

Informative References

  • CRI Profile v2.0: DE.CM
  • CSF v1.1: DE.CM
  • ISO/IEC 27001:2022: Mandatory Clause: 9.1
  • ISO/IEC 27001:2022: Annex A Controls: 8.16
  • NICE Framework: DD-WRL-005
  • NICE Framework: DD-WRL-007
  • NICE Framework: IO-WRL-004
  • NICE Framework: IO-WRL-005
  • NICE Framework: IO-WRL-006
  • NICE Framework: OG-WRL-016
  • NICE Framework: PD-WRL-001
  • NICE Framework: PD-WRL-004
  • NICE Framework: PD-WRL-005
  • SCF: MON-11.3
  • SCF: MON-16
  • SP-800-37 Rev 2: RMF Monitor Step

DE.CM-01

Networks and network services are monitored to find potentially adverse events

Implementation Examples

  • Ex1: Monitor DNS, BGP, and other network services for adverse events
  • Ex2: Monitor wired and wireless networks for connections from unauthorized endpoints
  • Ex3: Monitor facilities for unauthorized or rogue wireless networks
  • Ex4: Compare actual network flows against baselines to detect deviations
  • Ex5: Monitor network communications to identify changes in security postures for zero trust purposes

Informative References

  • AI-SOC: AI-SOC-02
  • AI-SOC: AI-SOC-15
  • CCMv4.0: IVS-03
  • CCMv4.0: IVS-09
  • CCMv4.0: LOG-01
  • CCMv4.0: LOG-03
  • CCMv4.0: LOG-05
  • CCMv4.0: LOG-08
  • CCMv4.0: TVM-02
  • CCMv4.0: TVM-10
  • CCMv4.0: UEM-10
  • CIS Controls v8.0: 13.1
  • CIS Controls v8.1: 13.1
  • CRI Profile v2.0: DE.CM-01
  • CRI Profile v2.0: DE.CM-01.01
  • CRI Profile v2.0: DE.CM-01.02
  • CRI Profile v2.0: DE.CM-01.03
  • CRI Profile v2.0: DE.CM-01.04
  • CRI Profile v2.0: DE.CM-01.05
  • CRI Profile v2.0: DE.CM-01.06
  • CSF v1.1: DE.CM-1
  • CSF v1.1: DE.CM-4
  • CSF v1.1: DE.CM-5
  • CSF v1.1: DE.CM-7
  • IRP: IRP-Sec-4
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 8.16
  • ISO/IEC 27001:2022: Control 8.15
  • NICE Framework: DD-WRL-007
  • NICE Framework: IO-WRL-004
  • NICE Framework: IO-WRL-006
  • NICE Framework: OG-WRL-016
  • NICE Framework: PD-WRL-001
  • NICE Framework: PD-WRL-004
  • OWASP Top 10 LLM Applications: LLM01-2025
  • OWASP Top 10 LLM Applications: LLM02-2025
  • OWASP Top 10 LLM Applications: LLM10-2025
  • PCI DSS: 10.2.1
  • PCI DSS: 10.4.1
  • PCI DSS: 11.2.1
  • PCI DSS: 1.2.4
  • SCF: MON-01
  • SCF: MON-01.1
  • SCF: MON-01.3
  • SCF: MON-01.4
  • SCF: MON-01.8
  • SDOS: SDOS-AU-01
  • SDOS: SDOS-AU-02
  • SDOS: SDOS-EN-04
  • SP 800-171 Rev 3: 03.01.01
  • SP 800-171 Rev 3: 03.03.03
  • SP 800-171 Rev 3: 03.04.03
  • SP 800-171 Rev 3: 03.12.03
  • SP 800-171 Rev 3: 03.13.01
  • SP 800-171 Rev 3: 03.13.06
  • SP 800-171 Rev 3: 03.14.06
  • SP 800-53 Rev 5.1.1: AC-02
  • SP 800-53 Rev 5.1.1: AU-12
  • SP 800-53 Rev 5.1.1: CA-07
  • SP 800-53 Rev 5.1.1: CM-03
  • SP 800-53 Rev 5.1.1: SC-05
  • SP 800-53 Rev 5.1.1: SC-07
  • SP 800-53 Rev 5.1.1: SI-04
  • SP 800-53 Rev 5.2.0: AC-02
  • SP 800-53 Rev 5.2.0: AU-12
  • SP 800-53 Rev 5.2.0: CA-07
  • SP 800-53 Rev 5.2.0: CM-03
  • SP 800-53 Rev 5.2.0: SC-05
  • SP 800-53 Rev 5.2.0: SC-07
  • SP 800-53 Rev 5.2.0: SI-04
  • SP 800-81r3: 2.1.2
  • SP 800-81r3: 2.1.3
  • SP 800-81r3: 3.6.1
  • SP 800-81r3: 3.6.2

DE.CM-02

The physical environment is monitored to find potentially adverse events

Implementation Examples

  • Ex1: Monitor logs from physical access control systems (e.g., badge readers) to find unusual access patterns (e.g., deviations from the norm) and failed access attempts
  • Ex2: Review and monitor physical access records (e.g., from visitor registration, sign-in sheets)
  • Ex3: Monitor physical access controls (e.g., locks, latches, hinge pins, alarms) for signs of tampering
  • Ex4: Monitor the physical environment using alarm systems, cameras, and security guards

Informative References

  • CCMv4.0: DCS-09
  • CCMv4.0: DCS-10
  • CCMv4.0: DCS-14
  • CCMv4.0: LOG-01
  • CCMv4.0: LOG-03
  • CCMv4.0: LOG-05
  • CCMv4.0: LOG-08
  • CCMv4.0: LOG-12
  • CCMv4.0: TVM-10
  • CRI Profile v2.0: DE.CM-02
  • CRI Profile v2.0: DE.CM-02.01
  • CSF v1.1: DE.CM-2
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 7.4
  • NICE Framework: DD-WRL-007
  • NICE Framework: IO-WRL-005
  • NICE Framework: IO-WRL-006
  • NICE Framework: OG-WRL-016
  • NICE Framework: PD-WRL-001
  • NICE Framework: PD-WRL-004
  • PCI DSS: 9.3.1.1
  • PCI DSS: 9.5.1.2
  • PCI DSS: 9.4.1.2
  • SCF: PES-01
  • SCF: PES-03
  • SCF: PES-03.3
  • SCF: PES-05
  • SP 800-171 Rev 3: 03.10.02
  • SP 800-171 Rev 3: 03.10.07
  • SP 800-171 Rev 3: 03.12.03
  • SP 800-53 Rev 5.1.1: CA-07
  • SP 800-53 Rev 5.1.1: PE-03
  • SP 800-53 Rev 5.1.1: PE-06
  • SP 800-53 Rev 5.1.1: PE-20
  • SP 800-53 Rev 5.2.0: CA-07
  • SP 800-53 Rev 5.2.0: PE-03
  • SP 800-53 Rev 5.2.0: PE-06
  • SP 800-53 Rev 5.2.0: PE-20

DE.CM-03

Personnel activity and technology usage are monitored to find potentially adverse events

Implementation Examples

  • Ex1: Use behavior analytics software to detect anomalous user activity to mitigate insider threats
  • Ex2: Monitor logs from logical access control systems to find unusual access patterns and failed access attempts
  • Ex3: Continuously monitor deception technology, including user accounts, for any usage

Informative References

  • AI-SOC: AI-SOC-09
  • AI-SOC: AI-SOC-19
  • CCMv4.0: LOG-01
  • CCMv4.0: LOG-03
  • CCMv4.0: LOG-05
  • CCMv4.0: LOG-08
  • CCMv4.0: TVM-10
  • CIS Controls v8.0: 10.7
  • CIS Controls v8.1: 10.7
  • CRI Profile v2.0: DE.CM-03
  • CRI Profile v2.0: DE.CM-03.01
  • CRI Profile v2.0: DE.CM-03.02
  • CRI Profile v2.0: DE.CM-03.03
  • CSF v1.1: DE.CM-3
  • CSF v1.1: DE.CM-7
  • Guardian-SDK: GS-PF-03
  • ISO/IEC 27001:2022: Mandatory Clause: 9.1
  • ISO/IEC 27001:2022: Annex A Controls: 7.4
  • ISO/IEC 27001:2022: Annex A Controls: 8.16
  • ISO/IEC 27001:2022: Control 8.16
  • NICE Framework: DD-WRL-007
  • NICE Framework: IO-WRL-006
  • NICE Framework: OG-WRL-016
  • NICE Framework: PD-WRL-001
  • NICE Framework: PD-WRL-004
  • NICE Framework: PD-WRL-005
  • OWASP Top 10 LLM Applications: LLM01-2025
  • OWASP Top 10 LLM Applications: LLM02-2025
  • OWASP Top 10 LLM Applications: LLM06-2025
  • PCI DSS: 10.2.1
  • PCI DSS: 10.4.1
  • PCI DSS: 8.2.2
  • PCI DSS: 10.6.1
  • SCF: MON-01
  • SCF: MON-16
  • SCF: NET-18
  • SDOS: SDOS-AU-01
  • SDOS: SDOS-AU-03
  • SP 800-171 Rev 3: 03.01.01
  • SP 800-171 Rev 3: 03.03.03
  • SP 800-171 Rev 3: 03.12.03
  • SP 800-53 Rev 5.1.1: AC-02
  • SP 800-53 Rev 5.1.1: AU-12
  • SP 800-53 Rev 5.1.1: AU-13
  • SP 800-53 Rev 5.1.1: CA-07
  • SP 800-53 Rev 5.1.1: CM-10
  • SP 800-53 Rev 5.1.1: CM-11
  • SP 800-53 Rev 5.2.0: AC-02
  • SP 800-53 Rev 5.2.0: AU-12
  • SP 800-53 Rev 5.2.0: AU-13
  • SP 800-53 Rev 5.2.0: CA-07
  • SP 800-53 Rev 5.2.0: CM-10
  • SP 800-53 Rev 5.2.0: CM-11
  • SP 800-81r3: 2.1.3

DE.CM-04

[Withdrawn: Incorporated into DE.CM-01, DE.CM-09]

DE.CM-05

[Withdrawn: Incorporated into DE.CM-01, DE.CM-09]

DE.CM-06

External service provider activities and services are monitored to find potentially adverse events

Implementation Examples

  • Ex1: Monitor remote and onsite administration and maintenance activities that external providers perform on organizational systems
  • Ex2: Monitor activity from cloud-based services, internet service providers, and other service providers for deviations from expected behavior

Informative References

  • AI-SOC: AI-SOC-26
  • AI-SOC: AI-SOC-11
  • CCMv4.0: LOG-01
  • CCMv4.0: LOG-03
  • CCMv4.0: LOG-05
  • CCMv4.0: LOG-08
  • CCMv4.0: TVM-10
  • CIS Controls v8.0: 15.2
  • CIS Controls v8.0: 15.6
  • CIS Controls v8.1: 15.2
  • CIS Controls v8.1: 15.6
  • CRI Profile v2.0: DE.CM-06
  • CRI Profile v2.0: DE.CM-06.01
  • CRI Profile v2.0: DE.CM-06.02
  • CSF v1.1: DE.CM-6
  • CSF v1.1: DE.CM-7
  • Guardian-SDK: GS-AG-02
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.22
  • ISO/IEC 27001:2022: Annex A Controls: 8.16
  • NICE Framework: DD-WRL-007
  • NICE Framework: IO-WRL-006
  • NICE Framework: OG-WRL-016
  • NICE Framework: PD-WRL-001
  • NICE Framework: PD-WRL-004
  • OWASP Top 10 LLM Applications: LLM03-2025
  • PCI DSS: 12.8.4
  • PCI DSS: 7.2.4
  • PCI DSS: 10.2.1
  • SCF: MON-01
  • SDOS: SDOS-AU-02
  • SDOS: SDOS-EN-04
  • SP 800-171 Rev 3: 03.12.03
  • SP 800-171 Rev 3: 03.14.06
  • SP 800-171 Rev 3: 03.16.03
  • SP 800-53 Rev 5.1.1: CA-07
  • SP 800-53 Rev 5.1.1: PS-07
  • SP 800-53 Rev 5.1.1: SA-04
  • SP 800-53 Rev 5.1.1: SA-09
  • SP 800-53 Rev 5.1.1: SI-04
  • SP 800-53 Rev 5.2.0: CA-07
  • SP 800-53 Rev 5.2.0: PS-07
  • SP 800-53 Rev 5.2.0: SA-04
  • SP 800-53 Rev 5.2.0: SA-09
  • SP 800-53 Rev 5.2.0: SI-04

DE.CM-07

[Withdrawn: Incorporated into DE.CM-01, DE.CM-03, DE.CM-06, DE.CM-09]

DE.CM-08

[Withdrawn: Incorporated into ID.RA-01]

DE.CM-09

Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events

Implementation Examples

  • Ex1: Monitor email, web, file sharing, collaboration services, and other common attack vectors to detect malware, phishing, data leaks and exfiltration, and other adverse events
  • Ex2: Monitor authentication attempts to identify attacks against credentials and unauthorized credential reuse
  • Ex3: Monitor software configurations for deviations from security baselines
  • Ex4: Monitor hardware and software for signs of tampering
  • Ex5: Use technologies with a presence on endpoints to detect cyber health issues (e.g., missing patches, malware infections, unauthorized software), and redirect the endpoints to a remediation environment before access is authorized

Informative References

  • AI-SOC: AI-SOC-02
  • AI-SOC: AI-SOC-03
  • CCMv4.0: CCC-07
  • CCMv4.0: IVS-06
  • CCMv4.0: LOG-01
  • CCMv4.0: LOG-03
  • CCMv4.0: LOG-05
  • CCMv4.0: LOG-08
  • CCMv4.0: LOG-10
  • CCMv4.0: LOG-11
  • CCMv4.0: TVM-02
  • CCMv4.0: TVM-10
  • CCMv4.0: UEM-09
  • CCMv4.0: UEM-10
  • CCMv4.0: UEM-11
  • CIS Controls v8.0: 10.1
  • CIS Controls v8.1: 10.1
  • CRI Profile v2.0: DE.CM-09
  • CRI Profile v2.0: DE.CM-09.01
  • CRI Profile v2.0: DE.CM-09.02
  • CRI Profile v2.0: DE.CM-09.03
  • CSF v1.1: PR.DS-6
  • CSF v1.1: PR.DS-8
  • CSF v1.1: DE.CM-4
  • CSF v1.1: DE.CM-5
  • CSF v1.1: DE.CM-7
  • Guardian-SDK: GS-PF-01
  • Guardian-SDK: GS-PF-02
  • Guardian-SDK: GS-PF-04
  • Guardian-SDK: GS-MM-01
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 8.16
  • ISO/IEC 27001:2022: Control 8.6
  • NICE Framework: DD-WRL-005
  • NICE Framework: DD-WRL-007
  • NICE Framework: IO-WRL-006
  • NICE Framework: OG-WRL-016
  • NICE Framework: PD-WRL-001
  • NICE Framework: PD-WRL-004
  • OWASP Top 10 LLM Applications: LLM01-2025
  • OWASP Top 10 LLM Applications: LLM04-2025
  • OWASP Top 10 LLM Applications: LLM05-2025
  • OWASP Top 10 LLM Applications: LLM08-2025
  • OWASP Top 10 LLM Applications: LLM10-2025
  • PCI DSS: 5.2.1
  • PCI DSS: 5.2.2
  • PCI DSS: 5.3.2
  • PCI DSS: 11.3.1
  • PCI DSS: 11.3.2
  • PCI DSS: 6.4.3
  • PCI DSS: 10.3.4
  • SCF: MON-01
  • SCF: MON-01.7
  • SCF: END-01
  • SCF: END-04
  • SCF: END-06
  • SDOS: SDOS-AU-02
  • SDOS: SDOS-IN-01
  • SDOS: SDOS-IN-03
  • SP 800-171 Rev 3: 03.01.03
  • SP 800-171 Rev 3: 03.03.03
  • SP 800-171 Rev 3: 03.04.02
  • SP 800-171 Rev 3: 03.04.03
  • SP 800-171 Rev 3: 03.12.03
  • SP 800-171 Rev 3: 03.14.06
  • SP 800-53 Rev 5.1.1: AC-04
  • SP 800-53 Rev 5.1.1: AC-09
  • SP 800-53 Rev 5.1.1: AU-12
  • SP 800-53 Rev 5.1.1: CA-07
  • SP 800-53 Rev 5.1.1: CM-03
  • SP 800-53 Rev 5.1.1: CM-06
  • SP 800-53 Rev 5.1.1: CM-10
  • SP 800-53 Rev 5.1.1: CM-11
  • SP 800-53 Rev 5.1.1: SC-34
  • SP 800-53 Rev 5.1.1: SC-35
  • SP 800-53 Rev 5.1.1: SI-04
  • SP 800-53 Rev 5.1.1: SI-07
  • SP 800-53 Rev 5.2.0: AC-04
  • SP 800-53 Rev 5.2.0: AC-09
  • SP 800-53 Rev 5.2.0: AU-12
  • SP 800-53 Rev 5.2.0: CA-07
  • SP 800-53 Rev 5.2.0: CM-03
  • SP 800-53 Rev 5.2.0: CM-06
  • SP 800-53 Rev 5.2.0: CM-10
  • SP 800-53 Rev 5.2.0: CM-11
  • SP 800-53 Rev 5.2.0: SC-34
  • SP 800-53 Rev 5.2.0: SC-35
  • SP 800-53 Rev 5.2.0: SI-04
  • SP 800-53 Rev 5.2.0: SI-07
  • SP 800-81r3: 2.1.3
  • SP 800-81r3: 3.6.3
  • SP 800-81r3: 4.2.4

Adverse Event Analysis (DE.AE)

Anomalies, indicators of compromise, and other potentially adverse events are analyzed to characterize the events and detect cybersecurity incidents

Informative References

  • CRI Profile v2.0: DE.AE
  • CSF v1.1: DE.AE
  • CSF v1.1: DE.DP-2
  • IRP: IRP-Sec-2
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.26
  • ISO/IEC 27001:2022: Annex A Controls: 8.16
  • NICE Framework: DD-WRL-004
  • NICE Framework: DD-WRL-008
  • NICE Framework: IO-WRL-001
  • NICE Framework: IO-WRL-006
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-010
  • NICE Framework: OG-WRL-012
  • NICE Framework: PD-WRL-001
  • NICE Framework: PD-WRL-003
  • NICE Framework: PD-WRL-005
  • NICE Framework: PD-WRL-006
  • NICE Framework: PD-WRL-007
  • SCF: MON-01
  • SCF: MON-01.8
  • SCF: MON-01.12
  • SCF: IRO-01
  • SCF: IRO-02
  • SCF: IRO-02.4

DE.AE-01

[Withdrawn: Incorporated into ID.AM-03]

DE.AE-02

Potentially adverse events are analyzed to better understand associated activities

Implementation Examples

  • Ex1: Use security information and event management (SIEM) or other tools to continuously monitor log events for known malicious and suspicious activity
  • Ex2: Utilize up-to-date cyber threat intelligence in log analysis tools to improve detection accuracy and characterize threat actors, their methods, and indicators of compromise
  • Ex3: Regularly conduct manual reviews of log events for technologies that cannot be sufficiently monitored through automation
  • Ex4: Use log analysis tools to generate reports on their findings

Informative References

  • AI-SOC: AI-SOC-01
  • AI-SOC: AI-SOC-13
  • CCMv4.0: LOG-03
  • CCMv4.0: LOG-05
  • CCMv4.0: SEF-05
  • CCMv4.0: SEF-06
  • CCMv4.0: UEM-09
  • CIS Controls v8.0: 8.11
  • CIS Controls v8.1: 8.11
  • CRI Profile v2.0: DE.AE-02
  • CRI Profile v2.0: DE.AE-02.01
  • CRI Profile v2.0: DE.AE-02.02
  • CSF v1.1: DE.AE-2
  • Guardian-SDK: GS-PF-04
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.24
  • ISO/IEC 27001:2022: Annex A Controls: 5.25
  • ISO/IEC 27001:2022: Control 5.25
  • NICE Framework: DD-WRL-008
  • NICE Framework: IO-WRL-006
  • NICE Framework: PD-WRL-001
  • NICE Framework: PD-WRL-005
  • NICE Framework: PD-WRL-006
  • NICE Framework: PD-WRL-007
  • OWASP Top 10 LLM Applications: LLM01-2025
  • OWASP Top 10 LLM Applications: LLM04-2025
  • OWASP Top 10 LLM Applications: LLM10-2025
  • PCI DSS: 10.2.1
  • PCI DSS: 10.4.1
  • PCI DSS: 10.4.2.1
  • PCI DSS: 10.3.3
  • PCI DSS: 10.3.4
  • PCI DSS: 6.3.1
  • SCF: IRO-02
  • SCF: IRO-02.4
  • SDOS: SDOS-DE-01
  • SDOS: SDOS-DE-02
  • SP 800-171 Rev 3: 03.03.05
  • SP 800-171 Rev 3: 03.06.01
  • SP 800-171 Rev 3: 03.12.03
  • SP 800-171 Rev 3: 03.14.06
  • SP 800-53 Rev 5.1.1: AU-06
  • SP 800-53 Rev 5.1.1: CA-07
  • SP 800-53 Rev 5.1.1: IR-04
  • SP 800-53 Rev 5.1.1: SI-04
  • SP 800-53 Rev 5.2.0: AU-06
  • SP 800-53 Rev 5.2.0: CA-07
  • SP 800-53 Rev 5.2.0: IR-04
  • SP 800-53 Rev 5.2.0: SI-04

DE.AE-03

Information is correlated from multiple sources

Implementation Examples

  • Ex1: Constantly transfer log data generated by other sources to a relatively small number of log servers
  • Ex2: Use event correlation technology (e.g., SIEM) to collect information captured by multiple sources
  • Ex3: Utilize cyber threat intelligence to help correlate events among log sources

Informative References

  • AI-SOC: AI-SOC-11
  • AI-SOC: AI-SOC-22
  • CCMv4.0: LOG-03
  • CCMv4.0: LOG-05
  • CCMv4.0: SEF-05
  • CRI Profile v2.0: DE.AE-03
  • CRI Profile v2.0: DE.AE-03.01
  • CRI Profile v2.0: DE.AE-03.02
  • CSF v1.1: DE.AE-3
  • Guardian-SDK: GS-PF-03
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 8.15
  • ISO/IEC 27001:2022: Annex A Controls: 8.16
  • NICE Framework: IO-WRL-001
  • NICE Framework: IO-WRL-006
  • NICE Framework: PD-WRL-001
  • NICE Framework: PD-WRL-006
  • OWASP Top 10 LLM Applications: LLM01-2025
  • OWASP Top 10 LLM Applications: LLM04-2025
  • PCI DSS: 10.2.1
  • PCI DSS: 10.3.3
  • PCI DSS: 10.4.1
  • PCI DSS: 12.5.1
  • PCI DSS: 1.2.4
  • SCF: MON-02
  • SCF: MON-02.1
  • SCF: IRO-02
  • SCF: IRO-02.5
  • SDOS: SDOS-AU-01
  • SDOS: SDOS-AU-02
  • SP 800-171 Rev 3: 03.03.05
  • SP 800-171 Rev 3: 03.06.01
  • SP 800-171 Rev 3: 03.06.02
  • SP 800-171 Rev 3: 03.06.05
  • SP 800-171 Rev 3: 03.12.03
  • SP 800-171 Rev 3: 03.14.06
  • SP 800-53 Rev 5.1.1: AU-06
  • SP 800-53 Rev 5.1.1: CA-07
  • SP 800-53 Rev 5.1.1: PM-16
  • SP 800-53 Rev 5.1.1: IR-04
  • SP 800-53 Rev 5.1.1: IR-05
  • SP 800-53 Rev 5.1.1: IR-08
  • SP 800-53 Rev 5.1.1: SI-04
  • SP 800-53 Rev 5.2.0: AU-06
  • SP 800-53 Rev 5.2.0: CA-07
  • SP 800-53 Rev 5.2.0: PM-16
  • SP 800-53 Rev 5.2.0: IR-04
  • SP 800-53 Rev 5.2.0: IR-05
  • SP 800-53 Rev 5.2.0: IR-08
  • SP 800-53 Rev 5.2.0: SI-04

DE.AE-04

The estimated impact and scope of adverse events are understood

Implementation Examples

  • Ex1: Use SIEMs or other tools to estimate impact and scope, and review and refine the estimates
  • Ex2: A person creates their own estimates of impact and scope

Informative References

  • AI-SOC: AI-SOC-06
  • AI-SOC: AI-SOC-13
  • CCMv4.0: LOG-03
  • CCMv4.0: SEF-05
  • CCMv4.0: SEF-06
  • CRI Profile v2.0: DE.AE-04
  • CRI Profile v2.0: DE.AE-04.01
  • CSF v1.1: DE.AE-4
  • Guardian-SDK: GS-PF-04
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.25
  • NICE Framework: DD-WRL-004
  • NICE Framework: IO-WRL-006
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-012
  • NICE Framework: PD-WRL-001
  • NICE Framework: PD-WRL-006
  • OWASP Top 10 LLM Applications: LLM01-2025
  • OWASP Top 10 LLM Applications: LLM02-2025
  • OWASP Top 10 LLM Applications: LLM04-2025
  • PCI DSS: 10.2.1
  • PCI DSS: 10.4.1
  • PCI DSS: 1.2.3
  • PCI DSS: 1.2.4
  • PCI DSS: 12.5.1
  • SCF: IRO-02
  • SCF: IRO-02.4
  • SDOS: SDOS-AU-01
  • SDOS: SDOS-RM-01
  • SP 800-53 Rev 5.1.1: PM-09
  • SP 800-53 Rev 5.1.1: PM-11
  • SP 800-53 Rev 5.1.1: PM-18
  • SP 800-53 Rev 5.1.1: PM-28
  • SP 800-53 Rev 5.1.1: PM-30
  • SP 800-53 Rev 5.2.0: PM-09
  • SP 800-53 Rev 5.2.0: PM-11
  • SP 800-53 Rev 5.2.0: PM-18
  • SP 800-53 Rev 5.2.0: PM-28
  • SP 800-53 Rev 5.2.0: PM-30

DE.AE-05

[Withdrawn: Moved to DE.AE-08]

DE.AE-06

Information on adverse events is provided to authorized staff and tools

Implementation Examples

  • Ex1: Use cybersecurity software to generate alerts and provide them to the security operations center (SOC), incident responders, and incident response tools
  • Ex2: Incident responders and other authorized personnel can access log analysis findings at all times
  • Ex3: Automatically create and assign tickets in the organization's ticketing system when certain types of alerts occur
  • Ex4: Manually create and assign tickets in the organization's ticketing system when technical staff discover indicators of compromise

Informative References

  • CCMv4.0: CCC-07
  • CCMv4.0: LOG-03
  • CCMv4.0: LOG-05
  • CCMv4.0: LOG-13
  • CCMv4.0: SEF-05
  • CCMv4.0: SEF-06
  • CRI Profile v2.0: DE.AE-06
  • CRI Profile v2.0: DE.AE-06.01
  • CSF v1.1: DE.DP-4
  • Guardian-SDK: GS-CF-02
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.26
  • NICE Framework: IO-WRL-006
  • NICE Framework: PD-WRL-001
  • NICE Framework: PD-WRL-005
  • NICE Framework: PD-WRL-006
  • NICE Framework: PD-WRL-007
  • PCI DSS: 12.10.1
  • PCI DSS: 10.3.1
  • PCI DSS: 10.3.3
  • PCI DSS: 12.10.3
  • SCF: MON-01.8
  • SCF: MON-01.12
  • SCF: MON-02
  • SCF: MON-02.1
  • SCF: IRO-02
  • SCF: IRO-02.4
  • SCF: IRO-04
  • SCF: IRO-07
  • SCF: IRO-09
  • SCF: IRO-10
  • SDOS: SDOS-AU-01
  • SDOS: SDOS-AU-03
  • SP 800-171 Rev 3: 03.06.01
  • SP 800-53 Rev 5.1.1: IR-04
  • SP 800-53 Rev 5.1.1: PM-15
  • SP 800-53 Rev 5.1.1: PM-16
  • SP 800-53 Rev 5.1.1: RA-03
  • SP 800-53 Rev 5.1.1: RA-10
  • SP 800-53 Rev 5.2.0: IR-04
  • SP 800-53 Rev 5.2.0: PM-15
  • SP 800-53 Rev 5.2.0: PM-16
  • SP 800-53 Rev 5.2.0: RA-04
  • SP 800-53 Rev 5.2.0: RA-10

DE.AE-07

Cyber threat intelligence and other contextual information are integrated into the analysis

Implementation Examples

  • Ex1: Securely provide cyber threat intelligence feeds to detection technologies, processes, and personnel
  • Ex2: Securely provide information from asset inventories to detection technologies, processes, and personnel
  • Ex3: Rapidly acquire and analyze vulnerability disclosures for the organization's technologies from suppliers, vendors, and third-party security advisories

Informative References

  • AI-SOC: AI-SOC-05
  • AI-SOC: AI-SOC-11
  • CCMv4.0: LOG-03
  • CCMv4.0: LOG-05
  • CCMv4.0: SEF-06
  • CRI Profile v2.0: DE.AE-07
  • CRI Profile v2.0: DE.AE-07.01
  • CRI Profile v2.0: DE.AE-07.02
  • CSF v1.1: DE.AE-3
  • Guardian-SDK: GS-PF-02
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.7
  • NICE Framework: DD-WRL-008
  • NICE Framework: IO-WRL-001
  • NICE Framework: IO-WRL-006
  • NICE Framework: PD-WRL-001
  • NICE Framework: PD-WRL-006
  • OWASP Top 10 LLM Applications: LLM01-2025
  • OWASP Top 10 LLM Applications: LLM03-2025
  • OWASP Top 10 LLM Applications: LLM04-2025
  • PCI DSS: 6.3.1
  • PCI DSS: 12.5.1
  • PCI DSS: 12.3.4
  • PCI DSS: 6.4.3
  • SCF: THR-01
  • SCF: THR-03
  • SDOS: SDOS-DE-01
  • SDOS: SDOS-RM-03
  • SP 800-171 Rev 3: 03.11.01
  • SP 800-53 Rev 5.1.1: PM-16
  • SP 800-53 Rev 5.1.1: RA-03
  • SP 800-53 Rev 5.1.1: RA-10
  • SP 800-53 Rev 5.2.0: PM-16
  • SP 800-53 Rev 5.2.0: RA-03
  • SP 800-53 Rev 5.2.0: RA-10

DE.AE-08

Incidents are declared when adverse events meet the defined incident criteria

Implementation Examples

  • Ex1: Apply incident criteria to known and assumed characteristics of activity in order to determine whether an incident should be declared
  • Ex2: Take known false positives into account when applying incident criteria

Informative References

  • CCMv4.0: LOG-03
  • CCMv4.0: LOG-05
  • CCMv4.0: SEF-02
  • CCMv4.0: SEF-06
  • CCMv4.0: SEF-07
  • CRI Profile v2.0: DE.AE-08
  • CRI Profile v2.0: DE.AE-08.01
  • CSF v1.1: DE.AE-5
  • Guardian-SDK: GS-PF-01
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.25
  • ISO/IEC 27001:2022: Annex A Controls: 5.26
  • NICE Framework: IO-WRL-006
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-010
  • NICE Framework: PD-WRL-001
  • NICE Framework: PD-WRL-003
  • NICE Framework: PD-WRL-006
  • PCI DSS: 12.10.1
  • PCI DSS: 12.10.2
  • PCI DSS: 12.10.4
  • SCF: IRO-02
  • SCF: IRO-02.4
  • SDOS: SDOS-AU-02
  • SDOS: SDOS-RS-01
  • SP 800-171 Rev 3: 03.06.05
  • SP 800-53 Rev 5.1.1: IR-04
  • SP 800-53 Rev 5.1.1: IR-08
  • SP 800-53 Rev 5.2.0: IR-04
  • SP 800-53 Rev 5.2.0: IR-08

Detection Processes (DE.DP)

[Withdrawn: Incorporated into other Categories and Functions]

DE.DP-01

[Withdrawn: Incorporated into GV.RR-02]

DE.DP-02

[Withdrawn: Incorporated into DE.AE]

DE.DP-03

[Withdrawn: Incorporated into ID.IM-02]

DE.DP-04

[Withdrawn: Incorporated into DE.AE-06]

DE.DP-05

[Withdrawn: Incorporated into ID.IM, ID.IM-03]