NIST Cybersecurity Framework 2.0
DE - Detect

NIST Cybersecurity Framework 2.0 NIST-CSF-DE.AE-06: Information on adverse events is provided to authorized staff and tools

Information on adverse events is provided to authorized staff and tools

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 78 controls across 31 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 8 controls

  • AU-5 Response to Audit Logging Process Failures
  • AU-6 Audit Record Review, Analysis, and Reporting
  • IR-6(3) Incident Reporting | Supply Chain Coordination (IR-6(3))
  • IR-7 Incident Response Assistance
  • IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1))
  • PE-13(2) Fire Protection | Suppression Systems: Automatic Activation and Notification (PE-13(2))
  • SI-4(5) System-Generated Alerts
  • SI-5 Security Alerts, Advisories, and Directives

FedRAMP Moderate · 8 controls

  • AU-5 Response to Audit Logging Process Failures
  • AU-6 Audit Record Review, Analysis, and Reporting
  • IR-6(3) Incident Reporting | Supply Chain Coordination (IR-6(3))
  • IR-7 Incident Response Assistance
  • IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1))
  • PE-13(2) Fire Protection | Suppression Systems: Automatic Activation and Notification (PE-13(2))
  • SI-4(5) System-Generated Alerts
  • SI-5 Security Alerts, Advisories, and Directives

NIST SP 800-53 Rev 5 · 7 controls

PCI DSS 4.0 · 6 controls

  • 10.4.1 10.4.1 Daily review of security-relevant logs
  • 10.7.1 10.7.1 Service providers detect critical control failures (superseded)
  • 10.7.2 10.7.2 Detect and alert on critical security control failures
  • 10.7.3 10.7.3 Respond promptly to critical security control failures
  • 11.6.1 11.6.1 Payment page tamper detection
  • 12.10.5 12.10.5 Plan covers alerts from security monitoring systems

CIS Controls v8 · 4 controls

  • CIS-13.1 Centralize Security Event Alerting
  • CIS-14.7 Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates
  • CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents
  • CIS-17.6 Define Mechanisms for Communicating During Incident Response

ISO 27001:2022 · 4 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.26 Response to information security incidents
  • 5.28 Collection of evidence
  • 8.15 Logging

ISO 27002:2022 · 4 controls

  • 5.26 Response to information security incidents
  • 5.28 Collection of evidence
  • 5.5 Contact with authorities
  • 6.8 Information security event reporting

SOC 2 · 4 controls

  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents
  • SOC2-CC7.4 CC7.4 Responding to security incidents
  • SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches

CMMC 2.0 · 3 controls

NIST SP 800-171 Rev 3 · 3 controls

  • 03.03.05 Audit Record Review, Analysis, and Reporting
  • 03.06.02 Incident Monitoring, Reporting, and Response Assistance
  • 03.14.03 Security Alerts, Advisories, and Directives
  • ISM-0123 Reporting incidents to the CISO
  • ISM-0733 CISO awareness of all incidents

HIPAA Security Rule · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

APRA CPS 234 · 1 control

  • CPS234-P25 Response Plan Content and Escalation Mechanisms
  • ASD37-30 Endpoint detection and response (Very Good)
  • SEC04-BP02 Capture logs, findings, and metrics in standardized locations
  • ASBv3-IR-2 Preparation - setup incident notification

C5 (Germany) · 1 control

  • C5-OPS-16 Logging and Monitoring - Configuration
  • CFTC-SS-16 Security Incident Response Plan and Testing

ISO 22301:2019 · 1 control

  • 8.4.3 Warning and communication

ISO 27701:2019 · 1 control

  • 6.13.1 Management of information security incidents and improvements

ISO/IEC 42001:2023 · 1 control

  • A.6.2.6 AI system operation and monitoring

NIS2 Directive · 1 control

  • DE.DP-4 DE.DP-4: Event detection information is communicated to appropriate parties
  • DE.DP-4 DE.DP-4: Event detection information is communicated

NIST SP 800-172 · 1 control

  • 3.6.1e Establish Security Operations Center (SOC)
  • DE.AE-06 DE.AE-06 Alerts and findings delivered to the SOC and responders, with ticketing
  • 3(c)(ii)(A) Sec. 3(c)(ii)(A) (now 3(a)(ii)(A)) Provide CISA the EDR and SOC data the concept of operations requires

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in DE - Detect

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-DE.AE-06 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 78 it maps to, and the evidence behind each claim, over MCP and REST.