NIST Cybersecurity Framework 2.0
DE - Detect

NIST Cybersecurity Framework 2.0 NIST-CSF-DE.AE-02: Potentially adverse events are analyzed to better understand associated activities

Potentially adverse events are analyzed to better understand associated activities. Control from NIST Cybersecurity Framework 2.0 framework, domain: DE - Detect.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 90 controls across 36 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 7 controls

  • AU-6 Audit Record Review, Analysis, and Reporting
  • AU-7(1) Automatic Processing
  • SI-4 System Monitoring
  • SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration (SI-4(18))
  • SI-4(2) Automated Tools and Mechanisms for Real-Time Analysis
  • SI-4(4) Inbound and Outbound Communications Traffic
  • SR-10 Inspection of Systems or Components (SR-10)

FedRAMP Moderate · 7 controls

  • AU-6 Audit Record Review, Analysis, and Reporting
  • AU-7(1) Automatic Processing
  • SI-4 System Monitoring
  • SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration (SI-4(18))
  • SI-4(2) Automated Tools and Mechanisms for Real-Time Analysis
  • SI-4(4) Inbound and Outbound Communications Traffic
  • SR-10 Inspection of Systems or Components (SR-10)

NIST SP 800-53 Rev 5 · 7 controls

PCI DSS 4.0 · 7 controls

  • 10.4.1 10.4.1 Daily review of security-relevant logs
  • 10.4.1.1 10.4.1.1 Automated mechanisms used for audit log review
  • 10.4.2 10.4.2 Periodic review of all other system component logs
  • 10.4.3 10.4.3 Exceptions and anomalies from log review addressed
  • 11.5.1.1 11.5.1.1 Service providers detect covert malware channels
  • 11.6.1 11.6.1 Payment page tamper detection
  • 5.4.1 5.4.1 Mechanisms detect and protect against phishing

CMMC 2.0 · 6 controls

SOC 2 · 5 controls

  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies
  • SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents
  • SOC2-CC7.5 CC7.5 Recovering from security incidents
  • SOC2-P6.2 P6.2 Record of authorised disclosures

CIS Controls v8 · 4 controls

  • CIS-10.7 Use Behavior-Based Anti-Malware Software
  • CIS-13.1 Centralize Security Event Alerting
  • CIS-13.11 Tune Security Event Alerting Thresholds
  • CIS-8.11 Conduct Audit Log Reviews

ISO 27001:2022 · 4 controls

  • 5.25 Assessment and decision on information security events
  • 5.28 Collection of evidence
  • 8.15 Logging
  • 8.16 Monitoring activities
  • ASBv3-IR-3 Detection and analysis - create incidents based on high-quality alerts
  • ASBv3-IR-4 Detection and analysis - investigate an incident
  • ASBv3-LT-1 Enable threat detection capabilities

NIST SP 800-171 Rev 3 · 3 controls

NIST SP 800-172 · 3 controls

  • 3.11.2e Threat Hunting
  • 3.11.3e Advanced Automation and Analytics Capabilities
  • 3.6.1e Establish Security Operations Center (SOC)
  • ASD37-28 Continuous incident detection and response (Excellent)
  • ASD37-31 Hunt to discover incidents (Very Good)
  • ISM-0120 Access to data sources and tools
  • ISM-1228 Analysing cyber security events for incidents

C2M2 · 2 controls

  • RESPONSE-1 Detect and Analyze Cybersecurity Events
  • SITUATION-2 Establish and Maintain a Common Operating Picture

C5 (Germany) · 2 controls

  • C5-OPS-13 Logging and Monitoring - Identification of Events
  • C5-SIM-02 Processing of security incidents

HIPAA Security Rule · 2 controls

ISO 27002:2022 · 2 controls

  • 5.25 Assessment and decision on information security events
  • 5.27 Learning from information security incidents

NIST SP 800-66 Rev 2 · 2 controls

  • E8-APP-ML2 Application Control (ML2)
  • ANSSI-HYG-36 Enable and Configure Logging on the Most Important Components

APRA CPS 234 · 1 control

  • AESCSF-SA-2 Anomaly and event detection
  • BE-CF-29 Audit record review and analysis
  • CFTC-SS-16 Security Incident Response Plan and Testing

DORA · 1 control

ISO 27701:2019 · 1 control

  • 6.13.1 Management of information security incidents and improvements

ISO/IEC 42001:2023 · 1 control

  • 9.1 Monitoring, measurement, analysis and evaluation

NIS2 Directive · 1 control

  • DE.AE-2 DE.AE-2: Detected events are analyzed to understand attack targets and methods
  • DE.AE-2 DE.AE-2: Detected events are analyzed to understand attack targets and methods
  • DE.AE-02 DE.AE-02 Log events analyzed with SIEM or SOAR tools, current CTI and manual review

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in DE - Detect

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-DE.AE-02 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 90 it maps to, and the evidence behind each claim, over MCP and REST.