NIST Cybersecurity Framework 2.0
DE - Detect

NIST Cybersecurity Framework 2.0 NIST-CSF-DE.CM-03: Personnel activity and technology usage are monitored to find potentially adverse events

Personnel activity and technology usage are monitored to find potentially adverse events. Control from NIST Cybersecurity Framework 2.0 framework, domain: DE - Detect.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 89 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 10 controls

CIS Controls v8 · 9 controls

  • CIS-13.1 Centralize Security Event Alerting
  • CIS-13.2 Deploy a Host-Based Intrusion Detection Solution
  • CIS-13.3 Deploy a Network Intrusion Detection Solution
  • CIS-3.14 Log Sensitive Data Access
  • CIS-8.11 Conduct Audit Log Reviews
  • CIS-8.2 Collect Audit Logs
  • CIS-8.5 Collect Detailed Audit Logs
  • CIS-8.7 Collect URL Request Audit Logs
  • CIS-8.8 Collect Command-Line Audit Logs

PCI DSS 4.0 · 8 controls

  • 10.2.1.1 10.2.1.1 Logs capture individual user access to cardholder data
  • 10.2.1.2 10.2.1.2 Logs capture all administrative actions
  • 10.2.1.4 10.2.1.4 Logs capture invalid logical access attempts
  • 10.2.1.5 10.2.1.5 Logs capture changes to identification and authentication credentials
  • 3.4.2 3.4.2 Remote access blocks copying or relocating PAN
  • 5.4.1 5.4.1 Mechanisms detect and protect against phishing
  • 9.2.3 9.2.3 Physical protection of network hardware and lines
  • 9.4.4 9.4.4 Management approval for media leaving facility

FedRAMP High · 7 controls

  • AC-2(12) Account Monitoring for Atypical Usage
  • AC-2(4) Automated Audit Actions
  • AU-6 Audit Record Review, Analysis, and Reporting
  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))
  • MA-3 Maintenance Tools (MA-3)
  • SI-4 System Monitoring

FedRAMP Moderate · 7 controls

  • AC-2(12) Account Monitoring for Atypical Usage
  • AC-2(4) Automated Audit Actions
  • AU-6 Audit Record Review, Analysis, and Reporting
  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))
  • MA-3 Maintenance Tools (MA-3)
  • SI-4 System Monitoring

CMMC 2.0 · 5 controls

SOC 2 · 5 controls

  • SOC2-CC3.3 CC3.3 Considering fraud risk (COSO principle 8)
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies
  • SOC2-P6.2 P6.2 Record of authorised disclosures
  • SOC2-P8.1 P8.1 Inquiries, complaints, disputes and compliance monitoring

ISO 27001:2022 · 4 controls

  • 5.25 Assessment and decision on information security events
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.15 Logging
  • 8.16 Monitoring activities
  • ISM-1509 Central logging of privileged access events
  • ISM-1566 Central logging of unprivileged access
  • ISM-1625 Insider threat mitigation program

ISO 27002:2022 · 3 controls

  • 5.10 Acceptable use of information and other associated assets
  • 8.16 Monitoring activities
  • 8.18 Use of privileged utility programs
  • SEC02-BP05 Audit and rotate credentials periodically
  • SEC04-BP01 Configure service and application logging

C5 (Germany) · 2 controls

HIPAA Security Rule · 2 controls

ISO 27701:2019 · 2 controls

  • 5.6 Operation
  • 6.9.4 Logging and monitoring
  • DE.CM-3 DE.CM-3: Personnel activity is monitored to detect potential cybersecurity events
  • DE.CM-7 DE.CM-7: Monitoring for unauthorized personnel, connections, devices, and software is performed
  • DE.CM-3 DE.CM-3: Personnel activity is monitored to detect potential cybersecurity events
  • DE.CM-7 DE.CM-7: Monitoring for unauthorized personnel, connections, devices, and software is performed

NIST SP 800-171 Rev 3 · 2 controls

  • 03.01.01 Account Management
  • 03.03.05 Audit Record Review, Analysis, and Reporting

NIST SP 800-66 Rev 2 · 2 controls

  • E8-ADMIN-ML2 Restrict Administrative Privileges (ML2)
  • ASD37-27 Outbound data loss prevention (Very Good)
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment
  • ASBv3-LT-2 Enable threat detection for identity and access management

NIST SP 800-172 · 1 control

  • DE.CM-03 DE.CM-03 Personnel activity and technology usage monitored for anomalies

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in DE - Detect

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-DE.CM-03 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 89 it maps to, and the evidence behind each claim, over MCP and REST.