NIST SP 800-61 Rev. 3
Detect (DE): incident response – NIST SP 800-61 Rev. 3

NIST SP 800-61 Rev. 3 DE.AE: DE.AE Adverse event analysis filtered by technology and aimed at early detection

CSF 2.0 Category: anomalies, indicators of compromise and other potentially adverse events are analyzed to characterize the events and detect cybersecurity incidents. Priority High. N1: analysis studies monitoring data to find attacks and compromises and to declare when an incident has occurred, starting response. R1: event volumes are high, so rely on technical solutions that filter large datasets to a subset suitable for human review. N2: event fidelity varies; anomalies may be benign or malicious; some incidents are easy to see, others need deep expertise. N3: CTI can be invaluable for early detection, lower impact and shorter recovery; signs become more obvious later in the attack life cycle but by then impact and scope may be much larger. R2: strive to find incidents earlier in the attack life cycle and take a proactive approach to detection and response. These items apply to every DE.AE Subcategory.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Detect (DE): incident response – NIST SP 800-61 Rev. 3

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.