DETECT (DE)¶
Possible cybersecurity attacks and compromises are found and analyzed
Informative References
- CRI Profile v2.0: DE
- CSF v1.1: DE
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 8.16
- SCF: THR-01
- SCF: THR-03
- SCF: THR-07
Continuous Monitoring (DE.CM)¶
Assets are monitored to find anomalies, indicators of compromise, and other potentially adverse events
Informative References
- CRI Profile v2.0: DE.CM
- CSF v1.1: DE.CM
- ISO/IEC 27001:2022: Mandatory Clause: 9.1
- ISO/IEC 27001:2022: Annex A Controls: 8.16
- NICE Framework: DD-WRL-005
- NICE Framework: DD-WRL-007
- NICE Framework: IO-WRL-004
- NICE Framework: IO-WRL-005
- NICE Framework: IO-WRL-006
- NICE Framework: OG-WRL-016
- NICE Framework: PD-WRL-001
- NICE Framework: PD-WRL-004
- NICE Framework: PD-WRL-005
- SCF: MON-11.3
- SCF: MON-16
- SP-800-37 Rev 2: RMF Monitor Step
DE.CM-01¶
Networks and network services are monitored to find potentially adverse events
Implementation Examples
- Ex1: Monitor DNS, BGP, and other network services for adverse events
- Ex2: Monitor wired and wireless networks for connections from unauthorized endpoints
- Ex3: Monitor facilities for unauthorized or rogue wireless networks
- Ex4: Compare actual network flows against baselines to detect deviations
- Ex5: Monitor network communications to identify changes in security postures for zero trust purposes
Informative References
- AI-SOC: AI-SOC-02
- AI-SOC: AI-SOC-15
- CCMv4.0: IVS-03
- CCMv4.0: IVS-09
- CCMv4.0: LOG-01
- CCMv4.0: LOG-03
- CCMv4.0: LOG-05
- CCMv4.0: LOG-08
- CCMv4.0: TVM-02
- CCMv4.0: TVM-10
- CCMv4.0: UEM-10
- CIS Controls v8.0: 13.1
- CIS Controls v8.1: 13.1
- CRI Profile v2.0: DE.CM-01
- CRI Profile v2.0: DE.CM-01.01
- CRI Profile v2.0: DE.CM-01.02
- CRI Profile v2.0: DE.CM-01.03
- CRI Profile v2.0: DE.CM-01.04
- CRI Profile v2.0: DE.CM-01.05
- CRI Profile v2.0: DE.CM-01.06
- CSF v1.1: DE.CM-1
- CSF v1.1: DE.CM-4
- CSF v1.1: DE.CM-5
- CSF v1.1: DE.CM-7
- IRP: IRP-Sec-4
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 8.16
- ISO/IEC 27001:2022: Control 8.15
- NICE Framework: DD-WRL-007
- NICE Framework: IO-WRL-004
- NICE Framework: IO-WRL-006
- NICE Framework: OG-WRL-016
- NICE Framework: PD-WRL-001
- NICE Framework: PD-WRL-004
- OWASP Top 10 LLM Applications: LLM01-2025
- OWASP Top 10 LLM Applications: LLM02-2025
- OWASP Top 10 LLM Applications: LLM10-2025
- PCI DSS: 10.2.1
- PCI DSS: 10.4.1
- PCI DSS: 11.2.1
- PCI DSS: 1.2.4
- SCF: MON-01
- SCF: MON-01.1
- SCF: MON-01.3
- SCF: MON-01.4
- SCF: MON-01.8
- SDOS: SDOS-AU-01
- SDOS: SDOS-AU-02
- SDOS: SDOS-EN-04
- SP 800-171 Rev 3: 03.01.01
- SP 800-171 Rev 3: 03.03.03
- SP 800-171 Rev 3: 03.04.03
- SP 800-171 Rev 3: 03.12.03
- SP 800-171 Rev 3: 03.13.01
- SP 800-171 Rev 3: 03.13.06
- SP 800-171 Rev 3: 03.14.06
- SP 800-53 Rev 5.1.1: AC-02
- SP 800-53 Rev 5.1.1: AU-12
- SP 800-53 Rev 5.1.1: CA-07
- SP 800-53 Rev 5.1.1: CM-03
- SP 800-53 Rev 5.1.1: SC-05
- SP 800-53 Rev 5.1.1: SC-07
- SP 800-53 Rev 5.1.1: SI-04
- SP 800-53 Rev 5.2.0: AC-02
- SP 800-53 Rev 5.2.0: AU-12
- SP 800-53 Rev 5.2.0: CA-07
- SP 800-53 Rev 5.2.0: CM-03
- SP 800-53 Rev 5.2.0: SC-05
- SP 800-53 Rev 5.2.0: SC-07
- SP 800-53 Rev 5.2.0: SI-04
- SP 800-81r3: 2.1.2
- SP 800-81r3: 2.1.3
- SP 800-81r3: 3.6.1
- SP 800-81r3: 3.6.2
DE.CM-02¶
The physical environment is monitored to find potentially adverse events
Implementation Examples
- Ex1: Monitor logs from physical access control systems (e.g., badge readers) to find unusual access patterns (e.g., deviations from the norm) and failed access attempts
- Ex2: Review and monitor physical access records (e.g., from visitor registration, sign-in sheets)
- Ex3: Monitor physical access controls (e.g., locks, latches, hinge pins, alarms) for signs of tampering
- Ex4: Monitor the physical environment using alarm systems, cameras, and security guards
Informative References
- CCMv4.0: DCS-09
- CCMv4.0: DCS-10
- CCMv4.0: DCS-14
- CCMv4.0: LOG-01
- CCMv4.0: LOG-03
- CCMv4.0: LOG-05
- CCMv4.0: LOG-08
- CCMv4.0: LOG-12
- CCMv4.0: TVM-10
- CRI Profile v2.0: DE.CM-02
- CRI Profile v2.0: DE.CM-02.01
- CSF v1.1: DE.CM-2
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 7.4
- NICE Framework: DD-WRL-007
- NICE Framework: IO-WRL-005
- NICE Framework: IO-WRL-006
- NICE Framework: OG-WRL-016
- NICE Framework: PD-WRL-001
- NICE Framework: PD-WRL-004
- PCI DSS: 9.3.1.1
- PCI DSS: 9.5.1.2
- PCI DSS: 9.4.1.2
- SCF: PES-01
- SCF: PES-03
- SCF: PES-03.3
- SCF: PES-05
- SP 800-171 Rev 3: 03.10.02
- SP 800-171 Rev 3: 03.10.07
- SP 800-171 Rev 3: 03.12.03
- SP 800-53 Rev 5.1.1: CA-07
- SP 800-53 Rev 5.1.1: PE-03
- SP 800-53 Rev 5.1.1: PE-06
- SP 800-53 Rev 5.1.1: PE-20
- SP 800-53 Rev 5.2.0: CA-07
- SP 800-53 Rev 5.2.0: PE-03
- SP 800-53 Rev 5.2.0: PE-06
- SP 800-53 Rev 5.2.0: PE-20
DE.CM-03¶
Personnel activity and technology usage are monitored to find potentially adverse events
Implementation Examples
- Ex1: Use behavior analytics software to detect anomalous user activity to mitigate insider threats
- Ex2: Monitor logs from logical access control systems to find unusual access patterns and failed access attempts
- Ex3: Continuously monitor deception technology, including user accounts, for any usage
Informative References
- AI-SOC: AI-SOC-09
- AI-SOC: AI-SOC-19
- CCMv4.0: LOG-01
- CCMv4.0: LOG-03
- CCMv4.0: LOG-05
- CCMv4.0: LOG-08
- CCMv4.0: TVM-10
- CIS Controls v8.0: 10.7
- CIS Controls v8.1: 10.7
- CRI Profile v2.0: DE.CM-03
- CRI Profile v2.0: DE.CM-03.01
- CRI Profile v2.0: DE.CM-03.02
- CRI Profile v2.0: DE.CM-03.03
- CSF v1.1: DE.CM-3
- CSF v1.1: DE.CM-7
- Guardian-SDK: GS-PF-03
- ISO/IEC 27001:2022: Mandatory Clause: 9.1
- ISO/IEC 27001:2022: Annex A Controls: 7.4
- ISO/IEC 27001:2022: Annex A Controls: 8.16
- ISO/IEC 27001:2022: Control 8.16
- NICE Framework: DD-WRL-007
- NICE Framework: IO-WRL-006
- NICE Framework: OG-WRL-016
- NICE Framework: PD-WRL-001
- NICE Framework: PD-WRL-004
- NICE Framework: PD-WRL-005
- OWASP Top 10 LLM Applications: LLM01-2025
- OWASP Top 10 LLM Applications: LLM02-2025
- OWASP Top 10 LLM Applications: LLM06-2025
- PCI DSS: 10.2.1
- PCI DSS: 10.4.1
- PCI DSS: 8.2.2
- PCI DSS: 10.6.1
- SCF: MON-01
- SCF: MON-16
- SCF: NET-18
- SDOS: SDOS-AU-01
- SDOS: SDOS-AU-03
- SP 800-171 Rev 3: 03.01.01
- SP 800-171 Rev 3: 03.03.03
- SP 800-171 Rev 3: 03.12.03
- SP 800-53 Rev 5.1.1: AC-02
- SP 800-53 Rev 5.1.1: AU-12
- SP 800-53 Rev 5.1.1: AU-13
- SP 800-53 Rev 5.1.1: CA-07
- SP 800-53 Rev 5.1.1: CM-10
- SP 800-53 Rev 5.1.1: CM-11
- SP 800-53 Rev 5.2.0: AC-02
- SP 800-53 Rev 5.2.0: AU-12
- SP 800-53 Rev 5.2.0: AU-13
- SP 800-53 Rev 5.2.0: CA-07
- SP 800-53 Rev 5.2.0: CM-10
- SP 800-53 Rev 5.2.0: CM-11
- SP 800-81r3: 2.1.3
DE.CM-04¶
[Withdrawn: Incorporated into DE.CM-01, DE.CM-09]
DE.CM-05¶
[Withdrawn: Incorporated into DE.CM-01, DE.CM-09]
DE.CM-06¶
External service provider activities and services are monitored to find potentially adverse events
Implementation Examples
- Ex1: Monitor remote and onsite administration and maintenance activities that external providers perform on organizational systems
- Ex2: Monitor activity from cloud-based services, internet service providers, and other service providers for deviations from expected behavior
Informative References
- AI-SOC: AI-SOC-26
- AI-SOC: AI-SOC-11
- CCMv4.0: LOG-01
- CCMv4.0: LOG-03
- CCMv4.0: LOG-05
- CCMv4.0: LOG-08
- CCMv4.0: TVM-10
- CIS Controls v8.0: 15.2
- CIS Controls v8.0: 15.6
- CIS Controls v8.1: 15.2
- CIS Controls v8.1: 15.6
- CRI Profile v2.0: DE.CM-06
- CRI Profile v2.0: DE.CM-06.01
- CRI Profile v2.0: DE.CM-06.02
- CSF v1.1: DE.CM-6
- CSF v1.1: DE.CM-7
- Guardian-SDK: GS-AG-02
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.22
- ISO/IEC 27001:2022: Annex A Controls: 8.16
- NICE Framework: DD-WRL-007
- NICE Framework: IO-WRL-006
- NICE Framework: OG-WRL-016
- NICE Framework: PD-WRL-001
- NICE Framework: PD-WRL-004
- OWASP Top 10 LLM Applications: LLM03-2025
- PCI DSS: 12.8.4
- PCI DSS: 7.2.4
- PCI DSS: 10.2.1
- SCF: MON-01
- SDOS: SDOS-AU-02
- SDOS: SDOS-EN-04
- SP 800-171 Rev 3: 03.12.03
- SP 800-171 Rev 3: 03.14.06
- SP 800-171 Rev 3: 03.16.03
- SP 800-53 Rev 5.1.1: CA-07
- SP 800-53 Rev 5.1.1: PS-07
- SP 800-53 Rev 5.1.1: SA-04
- SP 800-53 Rev 5.1.1: SA-09
- SP 800-53 Rev 5.1.1: SI-04
- SP 800-53 Rev 5.2.0: CA-07
- SP 800-53 Rev 5.2.0: PS-07
- SP 800-53 Rev 5.2.0: SA-04
- SP 800-53 Rev 5.2.0: SA-09
- SP 800-53 Rev 5.2.0: SI-04
DE.CM-07¶
[Withdrawn: Incorporated into DE.CM-01, DE.CM-03, DE.CM-06, DE.CM-09]
DE.CM-08¶
[Withdrawn: Incorporated into ID.RA-01]
DE.CM-09¶
Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
Implementation Examples
- Ex1: Monitor email, web, file sharing, collaboration services, and other common attack vectors to detect malware, phishing, data leaks and exfiltration, and other adverse events
- Ex2: Monitor authentication attempts to identify attacks against credentials and unauthorized credential reuse
- Ex3: Monitor software configurations for deviations from security baselines
- Ex4: Monitor hardware and software for signs of tampering
- Ex5: Use technologies with a presence on endpoints to detect cyber health issues (e.g., missing patches, malware infections, unauthorized software), and redirect the endpoints to a remediation environment before access is authorized
Informative References
- AI-SOC: AI-SOC-02
- AI-SOC: AI-SOC-03
- CCMv4.0: CCC-07
- CCMv4.0: IVS-06
- CCMv4.0: LOG-01
- CCMv4.0: LOG-03
- CCMv4.0: LOG-05
- CCMv4.0: LOG-08
- CCMv4.0: LOG-10
- CCMv4.0: LOG-11
- CCMv4.0: TVM-02
- CCMv4.0: TVM-10
- CCMv4.0: UEM-09
- CCMv4.0: UEM-10
- CCMv4.0: UEM-11
- CIS Controls v8.0: 10.1
- CIS Controls v8.1: 10.1
- CRI Profile v2.0: DE.CM-09
- CRI Profile v2.0: DE.CM-09.01
- CRI Profile v2.0: DE.CM-09.02
- CRI Profile v2.0: DE.CM-09.03
- CSF v1.1: PR.DS-6
- CSF v1.1: PR.DS-8
- CSF v1.1: DE.CM-4
- CSF v1.1: DE.CM-5
- CSF v1.1: DE.CM-7
- Guardian-SDK: GS-PF-01
- Guardian-SDK: GS-PF-02
- Guardian-SDK: GS-PF-04
- Guardian-SDK: GS-MM-01
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 8.16
- ISO/IEC 27001:2022: Control 8.6
- NICE Framework: DD-WRL-005
- NICE Framework: DD-WRL-007
- NICE Framework: IO-WRL-006
- NICE Framework: OG-WRL-016
- NICE Framework: PD-WRL-001
- NICE Framework: PD-WRL-004
- OWASP Top 10 LLM Applications: LLM01-2025
- OWASP Top 10 LLM Applications: LLM04-2025
- OWASP Top 10 LLM Applications: LLM05-2025
- OWASP Top 10 LLM Applications: LLM08-2025
- OWASP Top 10 LLM Applications: LLM10-2025
- PCI DSS: 5.2.1
- PCI DSS: 5.2.2
- PCI DSS: 5.3.2
- PCI DSS: 11.3.1
- PCI DSS: 11.3.2
- PCI DSS: 6.4.3
- PCI DSS: 10.3.4
- SCF: MON-01
- SCF: MON-01.7
- SCF: END-01
- SCF: END-04
- SCF: END-06
- SDOS: SDOS-AU-02
- SDOS: SDOS-IN-01
- SDOS: SDOS-IN-03
- SP 800-171 Rev 3: 03.01.03
- SP 800-171 Rev 3: 03.03.03
- SP 800-171 Rev 3: 03.04.02
- SP 800-171 Rev 3: 03.04.03
- SP 800-171 Rev 3: 03.12.03
- SP 800-171 Rev 3: 03.14.06
- SP 800-53 Rev 5.1.1: AC-04
- SP 800-53 Rev 5.1.1: AC-09
- SP 800-53 Rev 5.1.1: AU-12
- SP 800-53 Rev 5.1.1: CA-07
- SP 800-53 Rev 5.1.1: CM-03
- SP 800-53 Rev 5.1.1: CM-06
- SP 800-53 Rev 5.1.1: CM-10
- SP 800-53 Rev 5.1.1: CM-11
- SP 800-53 Rev 5.1.1: SC-34
- SP 800-53 Rev 5.1.1: SC-35
- SP 800-53 Rev 5.1.1: SI-04
- SP 800-53 Rev 5.1.1: SI-07
- SP 800-53 Rev 5.2.0: AC-04
- SP 800-53 Rev 5.2.0: AC-09
- SP 800-53 Rev 5.2.0: AU-12
- SP 800-53 Rev 5.2.0: CA-07
- SP 800-53 Rev 5.2.0: CM-03
- SP 800-53 Rev 5.2.0: CM-06
- SP 800-53 Rev 5.2.0: CM-10
- SP 800-53 Rev 5.2.0: CM-11
- SP 800-53 Rev 5.2.0: SC-34
- SP 800-53 Rev 5.2.0: SC-35
- SP 800-53 Rev 5.2.0: SI-04
- SP 800-53 Rev 5.2.0: SI-07
- SP 800-81r3: 2.1.3
- SP 800-81r3: 3.6.3
- SP 800-81r3: 4.2.4
Adverse Event Analysis (DE.AE)¶
Anomalies, indicators of compromise, and other potentially adverse events are analyzed to characterize the events and detect cybersecurity incidents
Informative References
- CRI Profile v2.0: DE.AE
- CSF v1.1: DE.AE
- CSF v1.1: DE.DP-2
- IRP: IRP-Sec-2
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.26
- ISO/IEC 27001:2022: Annex A Controls: 8.16
- NICE Framework: DD-WRL-004
- NICE Framework: DD-WRL-008
- NICE Framework: IO-WRL-001
- NICE Framework: IO-WRL-006
- NICE Framework: OG-WRL-002
- NICE Framework: OG-WRL-007
- NICE Framework: OG-WRL-010
- NICE Framework: OG-WRL-012
- NICE Framework: PD-WRL-001
- NICE Framework: PD-WRL-003
- NICE Framework: PD-WRL-005
- NICE Framework: PD-WRL-006
- NICE Framework: PD-WRL-007
- SCF: MON-01
- SCF: MON-01.8
- SCF: MON-01.12
- SCF: IRO-01
- SCF: IRO-02
- SCF: IRO-02.4
DE.AE-01¶
[Withdrawn: Incorporated into ID.AM-03]
DE.AE-02¶
Potentially adverse events are analyzed to better understand associated activities
Implementation Examples
- Ex1: Use security information and event management (SIEM) or other tools to continuously monitor log events for known malicious and suspicious activity
- Ex2: Utilize up-to-date cyber threat intelligence in log analysis tools to improve detection accuracy and characterize threat actors, their methods, and indicators of compromise
- Ex3: Regularly conduct manual reviews of log events for technologies that cannot be sufficiently monitored through automation
- Ex4: Use log analysis tools to generate reports on their findings
Informative References
- AI-SOC: AI-SOC-01
- AI-SOC: AI-SOC-13
- CCMv4.0: LOG-03
- CCMv4.0: LOG-05
- CCMv4.0: SEF-05
- CCMv4.0: SEF-06
- CCMv4.0: UEM-09
- CIS Controls v8.0: 8.11
- CIS Controls v8.1: 8.11
- CRI Profile v2.0: DE.AE-02
- CRI Profile v2.0: DE.AE-02.01
- CRI Profile v2.0: DE.AE-02.02
- CSF v1.1: DE.AE-2
- Guardian-SDK: GS-PF-04
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.24
- ISO/IEC 27001:2022: Annex A Controls: 5.25
- ISO/IEC 27001:2022: Control 5.25
- NICE Framework: DD-WRL-008
- NICE Framework: IO-WRL-006
- NICE Framework: PD-WRL-001
- NICE Framework: PD-WRL-005
- NICE Framework: PD-WRL-006
- NICE Framework: PD-WRL-007
- OWASP Top 10 LLM Applications: LLM01-2025
- OWASP Top 10 LLM Applications: LLM04-2025
- OWASP Top 10 LLM Applications: LLM10-2025
- PCI DSS: 10.2.1
- PCI DSS: 10.4.1
- PCI DSS: 10.4.2.1
- PCI DSS: 10.3.3
- PCI DSS: 10.3.4
- PCI DSS: 6.3.1
- SCF: IRO-02
- SCF: IRO-02.4
- SDOS: SDOS-DE-01
- SDOS: SDOS-DE-02
- SP 800-171 Rev 3: 03.03.05
- SP 800-171 Rev 3: 03.06.01
- SP 800-171 Rev 3: 03.12.03
- SP 800-171 Rev 3: 03.14.06
- SP 800-53 Rev 5.1.1: AU-06
- SP 800-53 Rev 5.1.1: CA-07
- SP 800-53 Rev 5.1.1: IR-04
- SP 800-53 Rev 5.1.1: SI-04
- SP 800-53 Rev 5.2.0: AU-06
- SP 800-53 Rev 5.2.0: CA-07
- SP 800-53 Rev 5.2.0: IR-04
- SP 800-53 Rev 5.2.0: SI-04
DE.AE-03¶
Information is correlated from multiple sources
Implementation Examples
- Ex1: Constantly transfer log data generated by other sources to a relatively small number of log servers
- Ex2: Use event correlation technology (e.g., SIEM) to collect information captured by multiple sources
- Ex3: Utilize cyber threat intelligence to help correlate events among log sources
Informative References
- AI-SOC: AI-SOC-11
- AI-SOC: AI-SOC-22
- CCMv4.0: LOG-03
- CCMv4.0: LOG-05
- CCMv4.0: SEF-05
- CRI Profile v2.0: DE.AE-03
- CRI Profile v2.0: DE.AE-03.01
- CRI Profile v2.0: DE.AE-03.02
- CSF v1.1: DE.AE-3
- Guardian-SDK: GS-PF-03
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 8.15
- ISO/IEC 27001:2022: Annex A Controls: 8.16
- NICE Framework: IO-WRL-001
- NICE Framework: IO-WRL-006
- NICE Framework: PD-WRL-001
- NICE Framework: PD-WRL-006
- OWASP Top 10 LLM Applications: LLM01-2025
- OWASP Top 10 LLM Applications: LLM04-2025
- PCI DSS: 10.2.1
- PCI DSS: 10.3.3
- PCI DSS: 10.4.1
- PCI DSS: 12.5.1
- PCI DSS: 1.2.4
- SCF: MON-02
- SCF: MON-02.1
- SCF: IRO-02
- SCF: IRO-02.5
- SDOS: SDOS-AU-01
- SDOS: SDOS-AU-02
- SP 800-171 Rev 3: 03.03.05
- SP 800-171 Rev 3: 03.06.01
- SP 800-171 Rev 3: 03.06.02
- SP 800-171 Rev 3: 03.06.05
- SP 800-171 Rev 3: 03.12.03
- SP 800-171 Rev 3: 03.14.06
- SP 800-53 Rev 5.1.1: AU-06
- SP 800-53 Rev 5.1.1: CA-07
- SP 800-53 Rev 5.1.1: PM-16
- SP 800-53 Rev 5.1.1: IR-04
- SP 800-53 Rev 5.1.1: IR-05
- SP 800-53 Rev 5.1.1: IR-08
- SP 800-53 Rev 5.1.1: SI-04
- SP 800-53 Rev 5.2.0: AU-06
- SP 800-53 Rev 5.2.0: CA-07
- SP 800-53 Rev 5.2.0: PM-16
- SP 800-53 Rev 5.2.0: IR-04
- SP 800-53 Rev 5.2.0: IR-05
- SP 800-53 Rev 5.2.0: IR-08
- SP 800-53 Rev 5.2.0: SI-04
DE.AE-04¶
The estimated impact and scope of adverse events are understood
Implementation Examples
- Ex1: Use SIEMs or other tools to estimate impact and scope, and review and refine the estimates
- Ex2: A person creates their own estimates of impact and scope
Informative References
- AI-SOC: AI-SOC-06
- AI-SOC: AI-SOC-13
- CCMv4.0: LOG-03
- CCMv4.0: SEF-05
- CCMv4.0: SEF-06
- CRI Profile v2.0: DE.AE-04
- CRI Profile v2.0: DE.AE-04.01
- CSF v1.1: DE.AE-4
- Guardian-SDK: GS-PF-04
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.25
- NICE Framework: DD-WRL-004
- NICE Framework: IO-WRL-006
- NICE Framework: OG-WRL-002
- NICE Framework: OG-WRL-012
- NICE Framework: PD-WRL-001
- NICE Framework: PD-WRL-006
- OWASP Top 10 LLM Applications: LLM01-2025
- OWASP Top 10 LLM Applications: LLM02-2025
- OWASP Top 10 LLM Applications: LLM04-2025
- PCI DSS: 10.2.1
- PCI DSS: 10.4.1
- PCI DSS: 1.2.3
- PCI DSS: 1.2.4
- PCI DSS: 12.5.1
- SCF: IRO-02
- SCF: IRO-02.4
- SDOS: SDOS-AU-01
- SDOS: SDOS-RM-01
- SP 800-53 Rev 5.1.1: PM-09
- SP 800-53 Rev 5.1.1: PM-11
- SP 800-53 Rev 5.1.1: PM-18
- SP 800-53 Rev 5.1.1: PM-28
- SP 800-53 Rev 5.1.1: PM-30
- SP 800-53 Rev 5.2.0: PM-09
- SP 800-53 Rev 5.2.0: PM-11
- SP 800-53 Rev 5.2.0: PM-18
- SP 800-53 Rev 5.2.0: PM-28
- SP 800-53 Rev 5.2.0: PM-30
DE.AE-05¶
[Withdrawn: Moved to DE.AE-08]
DE.AE-06¶
Information on adverse events is provided to authorized staff and tools
Implementation Examples
- Ex1: Use cybersecurity software to generate alerts and provide them to the security operations center (SOC), incident responders, and incident response tools
- Ex2: Incident responders and other authorized personnel can access log analysis findings at all times
- Ex3: Automatically create and assign tickets in the organization's ticketing system when certain types of alerts occur
- Ex4: Manually create and assign tickets in the organization's ticketing system when technical staff discover indicators of compromise
Informative References
- CCMv4.0: CCC-07
- CCMv4.0: LOG-03
- CCMv4.0: LOG-05
- CCMv4.0: LOG-13
- CCMv4.0: SEF-05
- CCMv4.0: SEF-06
- CRI Profile v2.0: DE.AE-06
- CRI Profile v2.0: DE.AE-06.01
- CSF v1.1: DE.DP-4
- Guardian-SDK: GS-CF-02
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.26
- NICE Framework: IO-WRL-006
- NICE Framework: PD-WRL-001
- NICE Framework: PD-WRL-005
- NICE Framework: PD-WRL-006
- NICE Framework: PD-WRL-007
- PCI DSS: 12.10.1
- PCI DSS: 10.3.1
- PCI DSS: 10.3.3
- PCI DSS: 12.10.3
- SCF: MON-01.8
- SCF: MON-01.12
- SCF: MON-02
- SCF: MON-02.1
- SCF: IRO-02
- SCF: IRO-02.4
- SCF: IRO-04
- SCF: IRO-07
- SCF: IRO-09
- SCF: IRO-10
- SDOS: SDOS-AU-01
- SDOS: SDOS-AU-03
- SP 800-171 Rev 3: 03.06.01
- SP 800-53 Rev 5.1.1: IR-04
- SP 800-53 Rev 5.1.1: PM-15
- SP 800-53 Rev 5.1.1: PM-16
- SP 800-53 Rev 5.1.1: RA-03
- SP 800-53 Rev 5.1.1: RA-10
- SP 800-53 Rev 5.2.0: IR-04
- SP 800-53 Rev 5.2.0: PM-15
- SP 800-53 Rev 5.2.0: PM-16
- SP 800-53 Rev 5.2.0: RA-04
- SP 800-53 Rev 5.2.0: RA-10
DE.AE-07¶
Cyber threat intelligence and other contextual information are integrated into the analysis
Implementation Examples
- Ex1: Securely provide cyber threat intelligence feeds to detection technologies, processes, and personnel
- Ex2: Securely provide information from asset inventories to detection technologies, processes, and personnel
- Ex3: Rapidly acquire and analyze vulnerability disclosures for the organization's technologies from suppliers, vendors, and third-party security advisories
Informative References
- AI-SOC: AI-SOC-05
- AI-SOC: AI-SOC-11
- CCMv4.0: LOG-03
- CCMv4.0: LOG-05
- CCMv4.0: SEF-06
- CRI Profile v2.0: DE.AE-07
- CRI Profile v2.0: DE.AE-07.01
- CRI Profile v2.0: DE.AE-07.02
- CSF v1.1: DE.AE-3
- Guardian-SDK: GS-PF-02
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.7
- NICE Framework: DD-WRL-008
- NICE Framework: IO-WRL-001
- NICE Framework: IO-WRL-006
- NICE Framework: PD-WRL-001
- NICE Framework: PD-WRL-006
- OWASP Top 10 LLM Applications: LLM01-2025
- OWASP Top 10 LLM Applications: LLM03-2025
- OWASP Top 10 LLM Applications: LLM04-2025
- PCI DSS: 6.3.1
- PCI DSS: 12.5.1
- PCI DSS: 12.3.4
- PCI DSS: 6.4.3
- SCF: THR-01
- SCF: THR-03
- SDOS: SDOS-DE-01
- SDOS: SDOS-RM-03
- SP 800-171 Rev 3: 03.11.01
- SP 800-53 Rev 5.1.1: PM-16
- SP 800-53 Rev 5.1.1: RA-03
- SP 800-53 Rev 5.1.1: RA-10
- SP 800-53 Rev 5.2.0: PM-16
- SP 800-53 Rev 5.2.0: RA-03
- SP 800-53 Rev 5.2.0: RA-10
DE.AE-08¶
Incidents are declared when adverse events meet the defined incident criteria
Implementation Examples
- Ex1: Apply incident criteria to known and assumed characteristics of activity in order to determine whether an incident should be declared
- Ex2: Take known false positives into account when applying incident criteria
Informative References
- CCMv4.0: LOG-03
- CCMv4.0: LOG-05
- CCMv4.0: SEF-02
- CCMv4.0: SEF-06
- CCMv4.0: SEF-07
- CRI Profile v2.0: DE.AE-08
- CRI Profile v2.0: DE.AE-08.01
- CSF v1.1: DE.AE-5
- Guardian-SDK: GS-PF-01
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.25
- ISO/IEC 27001:2022: Annex A Controls: 5.26
- NICE Framework: IO-WRL-006
- NICE Framework: OG-WRL-007
- NICE Framework: OG-WRL-010
- NICE Framework: PD-WRL-001
- NICE Framework: PD-WRL-003
- NICE Framework: PD-WRL-006
- PCI DSS: 12.10.1
- PCI DSS: 12.10.2
- PCI DSS: 12.10.4
- SCF: IRO-02
- SCF: IRO-02.4
- SDOS: SDOS-AU-02
- SDOS: SDOS-RS-01
- SP 800-171 Rev 3: 03.06.05
- SP 800-53 Rev 5.1.1: IR-04
- SP 800-53 Rev 5.1.1: IR-08
- SP 800-53 Rev 5.2.0: IR-04
- SP 800-53 Rev 5.2.0: IR-08
Detection Processes (DE.DP)¶
[Withdrawn: Incorporated into other Categories and Functions]
DE.DP-01¶
[Withdrawn: Incorporated into GV.RR-02]
DE.DP-02¶
[Withdrawn: Incorporated into DE.AE]
DE.DP-03¶
[Withdrawn: Incorporated into ID.IM-02]
DE.DP-04¶
[Withdrawn: Incorporated into DE.AE-06]
DE.DP-05¶
[Withdrawn: Incorporated into ID.IM, ID.IM-03]