NIST SP 800-137
Malware and Access Monitoring

NIST SP 800-137 6: Malware, Identity Access, and Network Boundary Monitoring

Monitor malware per Section 4.4 including signature-based AV + behavioral EDR + sandboxing + threat intel feed integration + Indicators of Compromise (IOCs) + Indicators of Attack (IOAs). Monitor identity and access per Section 4.5 including failed authentications + anomalous access + privilege escalations + after-hours access + UEBA (User and Entity Behavior Analytics) + impossible travel + dormant account use. Monitor network boundary per Section 4.6 including firewall logs + IDS/IPS + DLP + DNS + proxy + VPN + zero trust network access (ZTNA) + east-west traffic + microsegmentation effectiveness.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.