NIST Cybersecurity Framework 2.0 NIST-CSF-DE.AE-07: Cyber threat intelligence and other contextual information are integrated into the analysis
Cyber threat intelligence and other contextual information are integrated into the analysis
What else in your programme already covers this
This control maps to 62 controls across 32 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST800-PM-16 Threat Awareness Program. Implement a threat awareness program that includes a cross-organization information-sharing capability for threat intelligence
NIST800-SC-26 Decoys. Include components within organizational systems specifically designed to be the target of malicious attacks for detecting, deflecting, and analyzing such attacks
10.7.1 Critical security control failure detection (SP)
5.4.1 Processes and automated mechanisms are in place to detect and protect personnel against phishing attacks
6.3.1 Security vulnerabilities are identified and managed as follows: • New security vulnerabilities are identified using industry-recognized sources for security vulnerability information, including alerts from international and national computer emergency response teams (CERTs). • Vulnerabilities
SI-4(1) System Monitoring | System-wide Intrusion Detection System. Connect and configure individual intrusion detection tools into a system-wide intrusion detection system
SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration. Analyze outbound communications traffic at external interfaces to the system and at the following interior points to detect covert exfiltration of information: [Assignment: organization-defined interior points
SI-4(1) System Monitoring | System-wide Intrusion Detection System. Connect and configure individual intrusion detection tools into a system-wide intrusion detection system
SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration. Analyze outbound communications traffic at external interfaces to the system and at the following interior points to detect covert exfiltration of information: [Assignment: organization-defined interior points
You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?
NIST Cybersecurity Framework 2.0 NIST-CSF-DE.AE-07 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.