ASD Strategies to Mitigate Cyber Security Incidents
Detecting Cyber Security Incidents and Responding

ASD Strategies to Mitigate Cyber Security Incidents ASD37-32: Network-based IDS/IPS (Limited)

Network-based intrusion detection/prevention system using signatures and heuristics to identify anomalous traffic.

What else in your programme already covers this

This control maps to 106 controls across 61 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 6 controls

  • CA-8 Penetration Testing
  • IR-4 Incident Handling
  • SC-7 Boundary Protection
  • SI-4 System Monitoring
  • SI-4(1) System Monitoring | System-wide Intrusion Detection System. Connect and configure individual intrusion detection tools into a system-wide intrusion detection system
  • SI-4(4) Inbound and Outbound Communications Traffic

FedRAMP Moderate · 6 controls

  • CA-8 Penetration Testing
  • IR-4 Incident Handling
  • SC-7 Boundary Protection
  • SI-4 System Monitoring
  • SI-4(1) System Monitoring | System-wide Intrusion Detection System. Connect and configure individual intrusion detection tools into a system-wide intrusion detection system
  • SI-4(4) Inbound and Outbound Communications Traffic
  • CA-8 Penetration Testing
  • IR-4 Incident Handling
  • SC-7 Boundary Protection
  • SI-4 System Monitoring

NIST SP 800-53 Rev 5 · 3 controls

  • IR-4 Incident Handling
  • SC-7 Boundary Protection
  • SI-4 System Monitoring
  • IR-4 Incident Handling
  • SC-7 Boundary Protection
  • SI-4 System Monitoring

PCI DSS 4.0 · 3 controls

  • 11.5.1 IDS/IPS in place
  • 11.5.1.1 Covert malware channel detection (SP)
  • 12.10.5 IRP includes monitoring and response to security control alerts
  • ASBv3-LT-1 Enable threat detection capabilities
  • ASBv3-NS-4 Deploy intrusion detection/intrusion prevention systems (IDS/IPS)

C5 (Germany) · 2 controls

  • C5-COS-01 Technical safeguards
  • C5-COS-03 Monitoring of connections in the Cloud Service Provider's network

CIS Controls v8 · 2 controls

  • CIS-13.3 Deploy a Network Intrusion Detection Solution
  • CIS-13.8 Deploy a Network Intrusion Prevention Solution

CMMC 2.0 · 2 controls

ISO 27001:2022 · 2 controls

  • 8.16 Monitoring activities
  • 8.20 Networks security

ISO 27002:2022 · 2 controls

  • 8.16 Monitoring activities
  • 8.20 Networks security
  • NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring

SOC 2 · 2 controls

  • SOC2-CC6.6 Measures against threats outside system boundaries are implemented
  • SOC2-CC7.2 Monitors system components for anomalies indicating malicious acts

API 1164 · 1 control

  • AT-DSG-6 Sections 12-13 - Image processing (video surveillance/CCTV)

BSI IT-Grundschutz · 1 control

  • BSI-17 Continuous monitoring strategy

FISMA · 1 control

FedRAMP Rev 5 · 1 control

  • FedRAMP-ConMon Continuous Monitoring (ConMon) and Significant Change Requests
  • ICP-24 Macroprudential Surveillance and Insurance Supervision

IEC 62443 · 1 control

IEEE 1686 · 1 control

ISMAP (Japan) · 1 control

ISO 27017 · 1 control

ISO 27018 · 1 control

ISO 27019 · 1 control

ISO/IEC 27006:2024 · 1 control

ISO/IEC 27400:2022 · 1 control

  • 27400-6.5 Security monitoring and incident response

MTCS (Singapore) · 1 control

NERC CIP · 1 control

  • NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010)

NIST SP 1800-32 · 1 control

NIST SP 800-144 · 1 control

  • NISTSP144-8 Monitoring, Incident Response, Exit Strategy, and Compliance

NIST SP 800-145 · 1 control

  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 1 control

  • 3.12 Segment Data Processing and Storage Based on Sensitivity

NIST SP 800-190 · 1 control

  • NISTSP82-6 OT Audit, Monitoring, Anomaly Detection, and OT-Specific SOC
  • NZISM-5 Network Security, System Hardening, and Application Security
  • DSOMM-5 Information Gathering, Logging, Monitoring, and Incident Response
  • OMANCS-6 Security Monitoring, Detection, Incident Response, and OmanCERT Notification

South Korea ISMS-P · 1 control

  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Detecting Cyber Security Incidents and Responding

You are reading one control. How much of ASD Strategies to Mitigate Cyber Security Incidents have you already done?

ASD Strategies to Mitigate Cyber Security Incidents ASD37-32 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ASD Strategies to Mitigate Cyber Security Incidents your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 32 of 37 ASD Strategies to Mitigate Cyber Security Incidents controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 106 it maps to, and the evidence behind each claim, over MCP and REST.