Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-DE.CM-01 NIST Cybersecurity Framework 2.0
DE - Detect
NIST Cybersecurity Framework 2.0 NIST-CSF-DE.CM-01: Networks and network services are monitored to find potentially adverse events Networks and network services are monitored to find potentially adverse events. Control from NIST Cybersecurity Framework 2.0 framework, domain: DE - Detect.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 141 controls across 44 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
AC-17(1) Monitoring and Control AU-6(1) Automated Process Integration CA-7 Continuous Monitoring CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4)) IR-1 Policy and Procedures IR-5 Incident Monitoring SA-1 Policy and Procedures SA-2 Allocation of Resources SC-7 Boundary Protection SI-4 System Monitoring SI-4(1) System Monitoring | System-wide Intrusion Detection System (SI-4(1)) SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration (SI-4(18)) SI-4(2) Automated Tools and Mechanisms for Real-Time Analysis SI-4(4) Inbound and Outbound Communications Traffic SR-10 Inspection of Systems or Components (SR-10) AC-17(1) Monitoring and Control AU-6(1) Automated Process Integration CA-7 Continuous Monitoring CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4)) IR-1 Policy and Procedures IR-5 Incident Monitoring SA-1 Policy and Procedures SA-2 Allocation of Resources SC-7 Boundary Protection SI-4 System Monitoring SI-4(1) System Monitoring | System-wide Intrusion Detection System (SI-4(1)) SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration (SI-4(18)) SI-4(2) Automated Tools and Mechanisms for Real-Time Analysis SI-4(4) Inbound and Outbound Communications Traffic SR-10 Inspection of Systems or Components (SR-10) CIS-12.5 Centralize Network Authentication, Authorization, and Auditing (AAA) CIS-13.11 Tune Security Event Alerting Thresholds CIS-13.3 Deploy a Network Intrusion Detection Solution CIS-13.6 Collect Network Traffic Flow Logs CIS-13.8 Deploy a Network Intrusion Prevention Solution CIS-8.6 Collect DNS Query Audit Logs CIS-8.7 Collect URL Request Audit Logs CIS-9.2 Use DNS Filtering Services 10.7.1 10.7.1 Service providers detect critical control failures (superseded) 11.2.1 11.2.1 Detect authorized and rogue wireless access points 11.3.2 11.3.2 Quarterly ASV external vulnerability scans 11.5.1 11.5.1 IDS/IPS monitoring of CDE traffic 11.5.1.1 11.5.1.1 Service providers detect covert malware channels 11.6.1 11.6.1 Payment page tamper detection 12.10.5 12.10.5 Plan covers alerts from security monitoring systems 6.4.2 6.4.2 Automated web attack detection and prevention ASD37-07 Web content filtering (Excellent) ASD37-26 Software firewall - outbound (Very Good) ASD37-27 Outbound data loss prevention (Very Good) ASD37-28 Continuous incident detection and response (Excellent) ASD37-32 Network-based IDS/IPS (Limited) ASD37-33 Capture network traffic (Limited) 5.6 Operation 5.7.1 Monitoring, measurement, analysis and evaluation 6.10.1 Network security management 6.9 Operations security 6.9.4 Logging and monitoring 6.9.7 Information systems audit considerations 5.28 Collection of evidence 8.16 Monitoring activities 8.20 Networks security 8.21 Security of network services DE.CM-1 DE.CM-1: The network is monitored to detect potential cybersecurity events DE.CM-4 DE.CM-4: Malicious code is detected DE.CM-5 DE.CM-5: Unauthorized mobile code is detected DE.CM-7 DE.CM-7: Monitoring for unauthorized personnel, connections, devices, and software is performed DE.CM-1 DE.CM-1: The network is monitored to detect potential cybersecurity events DE.CM-4 DE.CM-4: Malicious code is detected DE.CM-5 DE.CM-5: Unauthorized mobile code is detected DE.CM-7 DE.CM-7: Monitoring for unauthorized personnel, connections, devices, and software is performed ISM-1028 NIDS or NIPS at external gateways ISM-1030 NIDS placement and firewall rule alerts ISM-1960 Analysing internet-facing network device event logs ASBv3-NS-4 Deploy intrusion detection/intrusion prevention systems (IDS/IPS) LT-3 Enable logging for security investigation LT-4 Enable network logging for security investigation C5-COS-01 Technical safeguards C5-COS-03 Monitoring of connections in the Cloud Service Provider's network C5-OPS-13 Logging and Monitoring - Identification of Events 8.16 Monitoring activities 8.20 Networks security 8.21 Security of network services 3.11.2e Threat Hunting 3.14.2e Monitor Organizational Systems with Specialized Capabilities 3.6.1e Establish Security Operations Center (SOC) SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16) SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities SOC2-CC7.2 CC7.2 Monitoring system components for anomalies SEC04-BP01 Configure service and application logging SEC05-BP03 Implement inspection-based protection ITSG33-RMP-6 Continuous Monitoring ITSG33-SI System and Information Integrity (SI) 9.1 Monitoring, measurement, analysis and evaluation 9.2.1 General E8-APP-ML2 Application Control (ML2) ADMF-6.1 Define monitoring and measurement scope AWWA-4.4 Audit Logging and Monitoring AUCDR-IS-5 Limit, prevent, detect and remove malware IRAP-OUT-3 Continuous monitoring and reassessment AESCSF-SA-1 Logging and monitoring BIMCO-8.1 Detection, logging, blocking and alerts EBA-GL-3.4.5 Security monitoring 9.1 Monitoring, measurement, analysis and evaluation DE.CM-01 DE.CM-01 Networks and network services monitored, including rogue networks Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in DE - Detect You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-DE.CM-01 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 141 it maps to, and the evidence behind each claim, over MCP and REST.