Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-DE.AE-08 What else in your programme already covers this This control maps to 270 controls across 146 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CA-9 Internal System Connections IR-1 Policy and Procedures IR-4(1) Automated Incident Handling Processes IR-5 Incident Monitoring IR-8 Incident Response Plan CA-9 Internal System Connections IR-1 Policy and Procedures IR-4(1) Automated Incident Handling Processes IR-5 Incident Monitoring IR-8 Incident Response Plan NRC7354-2 Critical Digital Asset (CDA) Identification, Scope, and Boundary NRC7354-4 Security Controls Implementation per NRC RG 5.71 Appendix B/C RG5.71-C.3 Cyber Security Training RG5.71-C.5 Recovery and Restoration RG5.71-C.6 Configuration Management DA-1 Enterprise Data Architecture DIQ-2 Data Quality Management RMD-1 Reference Data Management IEC62304-5.2 Software Requirements Analysis IEC62304-5.3 Software Architectural Design IEC62304-7.2 Risk Control Measures ISO-15189-5.1 Legal entity ISO-15189-5.4 Structure and authority ISO-15189-6.7 Service agreements ISO-19650-1-4 Information management concepts ISO-19650-1-7 Common Data Environment (CDE) concept ISO-19650-3-5.3 Trigger events for information exchange ISO-22320-5.1 General process requirements ISO-22320-5.3 Incident management structure (command) ISO-22320-5.4 Roles and responsibilities ISO23894-1 Scope of AI Risk Management ISO23894-3 AI-Specific Terminology ISO23894-6.2 Scope, Context and Criteria 27004-3 Terms and definitions 27004-A.2 Patching and Vulnerability Measures 27004-B.1 Example measurement definitions 27557-1 Scope 27557-3 Terms and definitions 27557-6.2 Scope, context, and criteria for privacy 29100-1 Scope 29100-3 Terms and definitions 29100-4.1 Actors and roles ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management ORANWG11-6 Security Test Specifications, Certification, and Conformance PICSGMP-2 Chapter 2: Personnel - Qualified Personnel, Key Responsibilities, Training PICSGMP-5 Chapter 5: Production Operations and Material Management PICSGMP-7 Chapter 7: Outsourced Activities and Supplier Management SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17) SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents SOC2-CC7.4 CC7.4 Responding to security incidents TRINIDAD-1 Scope, Definitions, Commission TRINIDAD-2 Lawful Processing and Consent TRINIDAD-3 Data Subject Rights Section 6(5) Definition of Foreign Public Official Section 8 Definition of Associated Person UKBRIBE-3 Due Diligence on Third Parties 58.1 Scope 58.3 Definitions AL-DPA-1 Scope and Definitions AL-DPA-3 Lawful Basis for Processing AT-DSG-2 Section 2 - Scope and application AT-DSG-8 Section 22 - Functions and powers of the DPA MLE.1 Machine Learning Requirements Analysis MLE.3 Machine Learning Training C5-OPS-13 Logging and Monitoring - Identification of Events C5-SIM-01 Policy for security incident management FEDRAMP-CM-6 Configuration Settings FEDRAMP-CP-9 System Backup FDBR-702 Definitions (§501.702) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) 60601-1.3 Terminology and definitions 60601-1.4.1 General requirements ISO-20400-4.2 Principles of sustainable procurement ISO-20400-7.2 Integrating sustainability into specifications 5.25 Assessment and decision on information security events 5.29 Information security during disruption 5.8.1 Nonconformity and corrective action 6.13.1 Management of information security incidents and improvements ISO-41001-4.1 Understanding the organization and its context ISO-41001-4.3 Determining the scope of the FM management system ISO-56002-4.3 Determining the scope of the innovation management system ISO-56002-8.3.4 Develop solutions ISO8000-DQM-02 Data Quality Dimensions ISO8000-MDG-03 Continuous Improvement ISO-17025-5.1 Legal entity ISO-17025-5.4 Personnel for the management system ISO-25012-5.2 Defining data quality measures ISO-25012-5.3 Planning and performing data quality evaluations 27011-1 Scope 27011-3 Terms and definitions 27014-1 Scope 27014-3 Terms and definitions 29147-3 Terms and definitions 29147-9.2 Contact mechanisms and scope 30111-3 Terms and definitions 30111-5.1 Organizational policy STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding Art.21.2.b Incident handling Art.23.1 Notify significant incidents to the CSIRT or competent authority, and warn affected service recipients NISTSP61-2 Computer Security Incident Response Team (CSIRT) Structure and Staffing DE.AE-08 DE.AE-08 Incidents declared by applying incident criteria NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation 12.10.5 12.10.5 Plan covers alerts from security monitoring systems 2.2.2 2.2.2 Vendor default accounts managed PICERL-P2 Risk Assessment PICERL-P3 CSIRT Formation SSAE18-CC7.4 CC7.4 - Incident Response SSAE18-PI1.1 PI1.1 - Processing Integrity Definition C1 Organizational Boundary C3 Scope 1 and 2 Coverage TANZANIA-1 Scope, Registration, Lawful Basis TANZANIA-4 Security and Cross-Border UKGAMBLE-1 Scope and Applicability to Licensees UKGAMBLE-4 Resilience and Incident Response US-SEC-DA-SC-01 Howey Test Application US-SEC-DA-SC-02 Registration Requirements CFR211-A-3 Section 211.3 - Definitions E8-APP-ML2 Application Control (ML2) ANSSI-HYG-40 Define a Security Incident Management Procedure CPS230-27 Identification and Escalation of Incidents and Near Misses CPS234-30 Detection and Response Mechanisms ASD37-28 Continuous incident detection and response (Excellent) 4.4.1 Resources, Roles, Responsibility, and Authority AWWA-1.1 Security Policy and Governance ISM-0043 Cyber security incident response plan contents AZ-DPA-2 Article 2 - Basic Concepts ASBv3-IR-3 Detection and analysis - create incidents based on high-quality alerts CFTC-SS-16 Security Incident Response Plan and Testing CIS-17.9 Establish and Maintain Security Incident Thresholds CPG-6.B Supply Chain Incident Reporting COBIT-BAI02 Managed requirements definition FFIEC-05 Roles and responsibilities definition FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2) Sapin2-Pillar1-Code-of-Conduct Pillar 1 - Anti-Corruption Code of Conduct ICP-1 Objectives, Powers and Responsibilities of the Supervisor IATA-IOSA-Section1-ORG-Organization-ManagementSystem-SMS IATA IOSA Section 1 - ORG Organization and Management System + Safety Management System (SMS) + Safety Policy + Hazard ID + Quality 62351-2 Glossary of terms ISO-14064-1-5.1 Organizational boundaries ISO-26262-3-5 Item definition 5.25 Assessment and decision on information security events ISO28001-PI-01 Personnel Security Screening ISO27003-4.3 Determining the scope of the information security management system 27007-5.2 Audit Programme Objectives ISO27043-04 Roles and responsibilities definition 27050-1.4 Terms and definitions 27400-3 Terms and definitions 29115-3 Terms and definitions 29134-3 Terms and definitions ISO21434-04 Roles and responsibilities definition BIPA-SEC5-1 Biometric Identifier Definition DE.AE-5 DE.AE-5: Incident alert thresholds are established DE.AE-5 DE.AE-5: Incident alert thresholds are established NISTSP115-1 Scope, Methodology, and Assessment Planning NISTSP137-1 ISCM Strategy, Governance, and Volatility Assessment NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition NISTSP146-1 Cloud Adoption Strategy, Workload Suitability, and Decision Framework 3.6.2e Establish and Maintain a Cyber Incident Response Team NISTSP63R4-1 Digital Identity Risk Management and IAL/AAL/FAL Assurance Level Selection NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP92-1 Log Management Programme, Policy, Roles, and Operational Runbooks OSFIB13-1 Governance, Risk Management, and Three Lines of Defense OWASPSAMM-1 Governance: Strategy, Policy, Compliance, Education, Champions OPENBANK-2 Strong Customer Authentication (SCA), Consent Lifecycle, and Customer UX OSSFSC-1 Branch Protection, Code Review, and Repository Governance PCI-P2PE-05 Roles and responsibilities definition PCI-PIN-05 Roles and responsibilities definition PCI-SSF-05 Roles and responsibilities definition PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements PTESPHASE-1 Pre-Engagement Interactions and Scoping PHILCC-1 Computer Crime Offences (Illegal Access, Interference, Misuse of Devices) RCEPEC-1 Online Personal Information Protection (12.13) RIDTPPA-1 Scope, Applicability, Definitions SHAREASSESS-1 Information Governance and Risk SUPCHAIN-1 Build Integrity - Source, Build, Provenance SCA-S2 Interpretation and Definitions IM8-RES.2 Disaster Recovery ISMSP-SYS-04 Vulnerability Management PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37 SWE-2 Relationship to GDPR FADP-5 Definitions (Article 5) UKGDPRREG-1 Subject Matter, Scope, Principles (Articles 1-11) OB-OPS.2 Performance Standards UK-TSA-NET-01 Security Architecture 15 U.S.C. § 78dd-2(h) Definition of Domestic Concern WCAGREC-3 Principle 3: Understandable SO2.2 Digital health architecture blueprint Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in DE - Detect You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-DE.AE-08 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 270 it maps to, and the evidence behind each claim, over MCP and REST.