CSF 2.0 Category: assets are monitored to find anomalies, indicators of compromise and other potentially adverse events. Priority High. R1: continuous monitoring for unauthorized activity, deviations from expected activity and changes in security posture should cover at all times networks and network services; computing hardware and software, runtime environments and their data; the physical environment; personnel activity and technology usage; and external service provider activities. C1: consider using cyber threat information with monitoring to spot malicious activity that might otherwise look benign. R2: tune monitoring technologies to bring false positives and false negatives to acceptable levels. These items apply to every DE.CM Subcategory.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.