Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-DE.CM-09 NIST Cybersecurity Framework 2.0
DE - Detect
NIST Cybersecurity Framework 2.0 NIST-CSF-DE.CM-09: Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 185 controls across 36 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CIS-1.2 Address Unauthorized Assets CIS-1.3 Utilize an Active Discovery Tool CIS-1.5 Use a Passive Asset Discovery Tool CIS-10.1 Deploy and Maintain Anti-Malware Software CIS-10.2 Configure Automatic Anti-Malware Signature Updates CIS-10.4 Configure Automatic Anti-Malware Scanning of Removable Media CIS-10.6 Centrally Manage Anti-Malware Software CIS-10.7 Use Behavior-Based Anti-Malware Software CIS-13.1 Centralize Security Event Alerting CIS-13.2 Deploy a Host-Based Intrusion Detection Solution CIS-13.3 Deploy a Network Intrusion Detection Solution CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution CIS-18.1 Establish and Maintain a Penetration Testing Program CIS-2.3 Address Unauthorized Software CIS-3.13 Deploy a Data Loss Prevention Solution CIS-7.4 Perform Automated Application Patch Management CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets CIS-8.1 Establish and Maintain an Audit Log Management Process CIS-8.2 Collect Audit Logs CIS-8.7 Collect URL Request Audit Logs CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections AC-17(1) Monitoring and Control CA-7 Continuous Monitoring CM-10 Software Usage Restrictions CM-11 User-Installed Software CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1)) CM-8(3) Automated Unauthorized Component Detection IR-5 Incident Monitoring RA-5 Vulnerability Monitoring and Scanning SA-1 Policy and Procedures SC-18 Mobile Code SI-4 System Monitoring SI-4(2) Automated Tools and Mechanisms for Real-Time Analysis SI-4(23) System Monitoring | Host-based Devices (SI-4(23)) SI-7 Software, Firmware, and Information Integrity SI-7(1) Integrity Checks SI-7(7) Integration of Detection and Response SR-10 Inspection of Systems or Components (SR-10) AC-17(1) Monitoring and Control CA-7 Continuous Monitoring CM-10 Software Usage Restrictions CM-11 User-Installed Software CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1)) CM-8(3) Automated Unauthorized Component Detection IR-5 Incident Monitoring RA-5 Vulnerability Monitoring and Scanning SA-1 Policy and Procedures SC-18 Mobile Code SI-4 System Monitoring SI-4(2) Automated Tools and Mechanisms for Real-Time Analysis SI-4(23) System Monitoring | Host-based Devices (SI-4(23)) SI-7 Software, Firmware, and Information Integrity SI-7(1) Integrity Checks SI-7(7) Integration of Detection and Response SR-10 Inspection of Systems or Components (SR-10) 10.4.1 10.4.1 Daily review of security-relevant logs 10.6.3 10.6.3 Time sync configuration and time data protected 10.7.1 10.7.1 Service providers detect critical control failures (superseded) 10.7.2 10.7.2 Detect and alert on critical security control failures 11.2.1 11.2.1 Detect authorized and rogue wireless access points 11.5.1.1 11.5.1.1 Service providers detect covert malware channels 11.5.2 11.5.2 Change detection on critical files 12.10.5 12.10.5 Plan covers alerts from security monitoring systems 12.6.1 12.6.1 Formal security awareness program 9.4.4 9.4.4 Management approval for media leaving facility 5.2.1 5.2.1 Anti-malware deployed on all system components 5.2.2 5.2.2 Anti-malware detects and handles all known malware 5.3.1 5.3.1 Anti-malware kept current through automatic updates 5.3.2 5.3.2 Periodic and real-time scans or continuous behavioural analysis 5.3.3 5.3.3 Anti-malware covers removable electronic media ASD37-05 Automated dynamic analysis of email and web content (Excellent) ASD37-06 Email content filtering (Excellent) ASD37-12 Antivirus software with heuristics (Very Good) ASD37-16 Antivirus software with signatures (Limited) ASD37-29 Host-based IDS/IPS (Very Good) ASD37-30 Endpoint detection and response (Very Good) ASBv3-GS-9 Define and implement endpoint security strategy ASBv3-LT-1 Enable threat detection capabilities ASBv3-PV-4 Audit and enforce secure configurations for compute resources DP-2 Monitor anomalies and threats targeting sensitive data ES-1 Use Endpoint Detection and Response (EDR) ES-2 Use modern anti-malware software 5.7.1 Monitoring, measurement, analysis and evaluation 6.9 Operations security 6.9.2 Protection from malware 6.9.4 Logging and monitoring 6.9.7 Information systems audit considerations 7.5.3 Records of transfer of PII 5.28 Collection of evidence 8.12 Data leakage prevention 8.16 Monitoring activities 8.18 Use of privileged utility programs 8.7 Protection against malware DE.CM-4 DE.CM-4: Malicious code is detected DE.CM-5 DE.CM-5: Unauthorized mobile code is detected DE.CM-7 DE.CM-7: Monitoring for unauthorized personnel, connections, devices, and software is performed PR.DS-6 PR.DS-6: Integrity checking mechanisms are used to verify software, firmware, and information integrity PR.DS-8 PR.DS-8: Integrity checking mechanisms are used to verify hardware integrity ISM-0109 Analysing workstation event logs ISM-1034 HIPS or EDR on critical servers ISM-1341 HIPS or EDR on workstations ISM-1986 Analysing critical server event logs C5-OPS-05 Protection Against Malware - Implementation C5-OPS-10 Logging and Monitoring - Concept C5-OPS-13 Logging and Monitoring - Identification of Events C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept 8.12 Data leakage prevention 8.15 Logging 8.16 Monitoring activities 8.7 Protection against malware DE.CM-4 DE.CM-4: Malicious code is detected DE.CM-5 DE.CM-5: Unauthorized mobile code is detected DE.CM-7 DE.CM-7: Monitoring for unauthorized personnel, connections, devices, and software is performed PR.DS-6 PR.DS-6: Integrity checking mechanisms are used to verify software, firmware, and information integrity SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities SOC2-CC7.2 CC7.2 Monitoring system components for anomalies SOC2-PI1.1 PI1.1 Quality information about processing objectives, data definitions and specifications 3.14.1e Verify Integrity of Security Critical Software and Firmware 3.14.2e Monitor Organizational Systems with Specialized Capabilities 3.4.2e Automated Detection and Remediation of Unauthorized Software E8-APP-ML3 Application Control (ML3) E8-UAH-ML3 User Application Hardening - Maturity Level 3 ANSSI-HYG-24 Protect the Corporate Mail Service ANSSI-HYG-36 Enable and Configure Logging on the Most Important Components 9.1 Monitoring, measurement, analysis and evaluation 9.2.1 General 9.1 Monitoring, measurement, analysis and evaluation A.6.2.6 AI system operation and monitoring CE-MP.1 Anti-Malware Software Deployed CE-MP.3 Anti-Malware Scans Files on Access and Web Pages 3(c)(v) Sec. 3(c)(v) (now 3(a)(v)) Enroll EDR endpoints in CISA's Persistent Access Capability 3(e)(i)(B) Sec. 3(e)(i)(B) (now 3(c)(i)(B)) Detect, report and recover from anomalous space system activity AWWA-4.1 Malware Protection AUCDR-IS-5 Limit, prevent, detect and remove malware Art.21.2.g Basic cyber hygiene practices and cybersecurity training DE.CM-09 DE.CM-09 Computing environments monitored for malware, credential attacks, drift, tampering and endpoint health Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in DE - Detect You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-DE.CM-09 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 185 it maps to, and the evidence behind each claim, over MCP and REST.