NIST Cybersecurity Framework 2.0
DE - Detect

NIST Cybersecurity Framework 2.0 NIST-CSF-DE.CM-09: Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events

Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 185 controls across 36 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 21 controls

  • CIS-1.2 Address Unauthorized Assets
  • CIS-1.3 Utilize an Active Discovery Tool
  • CIS-1.5 Use a Passive Asset Discovery Tool
  • CIS-10.1 Deploy and Maintain Anti-Malware Software
  • CIS-10.2 Configure Automatic Anti-Malware Signature Updates
  • CIS-10.4 Configure Automatic Anti-Malware Scanning of Removable Media
  • CIS-10.6 Centrally Manage Anti-Malware Software
  • CIS-10.7 Use Behavior-Based Anti-Malware Software
  • CIS-13.1 Centralize Security Event Alerting
  • CIS-13.2 Deploy a Host-Based Intrusion Detection Solution
  • CIS-13.3 Deploy a Network Intrusion Detection Solution
  • CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution
  • CIS-18.1 Establish and Maintain a Penetration Testing Program
  • CIS-2.3 Address Unauthorized Software
  • CIS-3.13 Deploy a Data Loss Prevention Solution
  • CIS-7.4 Perform Automated Application Patch Management
  • CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets
  • CIS-8.1 Establish and Maintain an Audit Log Management Process
  • CIS-8.2 Collect Audit Logs
  • CIS-8.7 Collect URL Request Audit Logs
  • CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections

FedRAMP High · 17 controls

  • AC-17(1) Monitoring and Control
  • CA-7 Continuous Monitoring
  • CM-10 Software Usage Restrictions
  • CM-11 User-Installed Software
  • CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1))
  • CM-8(3) Automated Unauthorized Component Detection
  • IR-5 Incident Monitoring
  • RA-5 Vulnerability Monitoring and Scanning
  • SA-1 Policy and Procedures
  • SC-18 Mobile Code
  • SI-4 System Monitoring
  • SI-4(2) Automated Tools and Mechanisms for Real-Time Analysis
  • SI-4(23) System Monitoring | Host-based Devices (SI-4(23))
  • SI-7 Software, Firmware, and Information Integrity
  • SI-7(1) Integrity Checks
  • SI-7(7) Integration of Detection and Response
  • SR-10 Inspection of Systems or Components (SR-10)

FedRAMP Moderate · 17 controls

  • AC-17(1) Monitoring and Control
  • CA-7 Continuous Monitoring
  • CM-10 Software Usage Restrictions
  • CM-11 User-Installed Software
  • CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1))
  • CM-8(3) Automated Unauthorized Component Detection
  • IR-5 Incident Monitoring
  • RA-5 Vulnerability Monitoring and Scanning
  • SA-1 Policy and Procedures
  • SC-18 Mobile Code
  • SI-4 System Monitoring
  • SI-4(2) Automated Tools and Mechanisms for Real-Time Analysis
  • SI-4(23) System Monitoring | Host-based Devices (SI-4(23))
  • SI-7 Software, Firmware, and Information Integrity
  • SI-7(1) Integrity Checks
  • SI-7(7) Integration of Detection and Response
  • SR-10 Inspection of Systems or Components (SR-10)

NIST SP 800-53 Rev 5 · 16 controls

PCI DSS 4.0 · 15 controls

  • 10.4.1 10.4.1 Daily review of security-relevant logs
  • 10.6.3 10.6.3 Time sync configuration and time data protected
  • 10.7.1 10.7.1 Service providers detect critical control failures (superseded)
  • 10.7.2 10.7.2 Detect and alert on critical security control failures
  • 11.2.1 11.2.1 Detect authorized and rogue wireless access points
  • 11.5.1.1 11.5.1.1 Service providers detect covert malware channels
  • 11.5.2 11.5.2 Change detection on critical files
  • 12.10.5 12.10.5 Plan covers alerts from security monitoring systems
  • 12.6.1 12.6.1 Formal security awareness program
  • 9.4.4 9.4.4 Management approval for media leaving facility
  • 5.2.1 5.2.1 Anti-malware deployed on all system components
  • 5.2.2 5.2.2 Anti-malware detects and handles all known malware
  • 5.3.1 5.3.1 Anti-malware kept current through automatic updates
  • 5.3.2 5.3.2 Periodic and real-time scans or continuous behavioural analysis
  • 5.3.3 5.3.3 Anti-malware covers removable electronic media

CMMC 2.0 · 8 controls

  • ASD37-05 Automated dynamic analysis of email and web content (Excellent)
  • ASD37-06 Email content filtering (Excellent)
  • ASD37-12 Antivirus software with heuristics (Very Good)
  • ASD37-16 Antivirus software with signatures (Limited)
  • ASD37-29 Host-based IDS/IPS (Very Good)
  • ASD37-30 Endpoint detection and response (Very Good)
  • ASBv3-GS-9 Define and implement endpoint security strategy
  • ASBv3-LT-1 Enable threat detection capabilities
  • ASBv3-PV-4 Audit and enforce secure configurations for compute resources
  • DP-2 Monitor anomalies and threats targeting sensitive data
  • ES-1 Use Endpoint Detection and Response (EDR)
  • ES-2 Use modern anti-malware software

ISO 27701:2019 · 6 controls

  • 5.7.1 Monitoring, measurement, analysis and evaluation
  • 6.9 Operations security
  • 6.9.2 Protection from malware
  • 6.9.4 Logging and monitoring
  • 6.9.7 Information systems audit considerations
  • 7.5.3 Records of transfer of PII

NIST SP 800-171 Rev 3 · 6 controls

ISO 27002:2022 · 5 controls

  • 5.28 Collection of evidence
  • 8.12 Data leakage prevention
  • 8.16 Monitoring activities
  • 8.18 Use of privileged utility programs
  • 8.7 Protection against malware
  • DE.CM-4 DE.CM-4: Malicious code is detected
  • DE.CM-5 DE.CM-5: Unauthorized mobile code is detected
  • DE.CM-7 DE.CM-7: Monitoring for unauthorized personnel, connections, devices, and software is performed
  • PR.DS-6 PR.DS-6: Integrity checking mechanisms are used to verify software, firmware, and information integrity
  • PR.DS-8 PR.DS-8: Integrity checking mechanisms are used to verify hardware integrity
  • ISM-0109 Analysing workstation event logs
  • ISM-1034 HIPS or EDR on critical servers
  • ISM-1341 HIPS or EDR on workstations
  • ISM-1986 Analysing critical server event logs

C5 (Germany) · 4 controls

  • C5-OPS-05 Protection Against Malware - Implementation
  • C5-OPS-10 Logging and Monitoring - Concept
  • C5-OPS-13 Logging and Monitoring - Identification of Events
  • C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept

ISO 27001:2022 · 4 controls

  • 8.12 Data leakage prevention
  • 8.15 Logging
  • 8.16 Monitoring activities
  • 8.7 Protection against malware
  • DE.CM-4 DE.CM-4: Malicious code is detected
  • DE.CM-5 DE.CM-5: Unauthorized mobile code is detected
  • DE.CM-7 DE.CM-7: Monitoring for unauthorized personnel, connections, devices, and software is performed
  • PR.DS-6 PR.DS-6: Integrity checking mechanisms are used to verify software, firmware, and information integrity

SOC 2 · 4 controls

  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies
  • SOC2-PI1.1 PI1.1 Quality information about processing objectives, data definitions and specifications

NIST SP 800-172 · 3 controls

  • 3.14.1e Verify Integrity of Security Critical Software and Firmware
  • 3.14.2e Monitor Organizational Systems with Specialized Capabilities
  • 3.4.2e Automated Detection and Remediation of Unauthorized Software

ACSC Essential Eight · 2 controls

  • E8-APP-ML3 Application Control (ML3)
  • E8-UAH-ML3 User Application Hardening - Maturity Level 3
  • ANSSI-HYG-24 Protect the Corporate Mail Service
  • ANSSI-HYG-36 Enable and Configure Logging on the Most Important Components

HIPAA Security Rule · 2 controls

ISO 22301:2019 · 2 controls

  • 9.1 Monitoring, measurement, analysis and evaluation
  • 9.2.1 General

ISO/IEC 42001:2023 · 2 controls

  • 9.1 Monitoring, measurement, analysis and evaluation
  • A.6.2.6 AI system operation and monitoring

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

UK Cyber Essentials · 2 controls

  • CE-MP.1 Anti-Malware Software Deployed
  • CE-MP.3 Anti-Malware Scans Files on Access and Web Pages
  • 3(c)(v) Sec. 3(c)(v) (now 3(a)(v)) Enroll EDR endpoints in CISA's Persistent Access Capability
  • 3(e)(i)(B) Sec. 3(e)(i)(B) (now 3(c)(i)(B)) Detect, report and recover from anomalous space system activity
  • AUCDR-IS-5 Limit, prevent, detect and remove malware

DORA · 1 control

NIS2 Directive · 1 control

  • Art.21.2.g Basic cyber hygiene practices and cybersecurity training

NIST SP 800-218 · 1 control

  • DE.CM-09 DE.CM-09 Computing environments monitored for malware, credential attacks, drift, tampering and endpoint health

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in DE - Detect

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-DE.CM-09 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 185 it maps to, and the evidence behind each claim, over MCP and REST.