NIST SP 800-61 Rev. 3
Detect (DE): incident response – NIST SP 800-61 Rev. 3

NIST SP 800-61 Rev. 3 DE.CM: DE.CM Continuous monitoring of all asset types at all times, tuned and informed by threat information

CSF 2.0 Category: assets are monitored to find anomalies, indicators of compromise and other potentially adverse events. Priority High. R1: continuous monitoring for unauthorized activity, deviations from expected activity and changes in security posture should cover at all times networks and network services; computing hardware and software, runtime environments and their data; the physical environment; personnel activity and technology usage; and external service provider activities. C1: consider using cyber threat information with monitoring to spot malicious activity that might otherwise look benign. R2: tune monitoring technologies to bring false positives and false negatives to acceptable levels. These items apply to every DE.CM Subcategory.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Detect (DE): incident response – NIST SP 800-61 Rev. 3

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.