NIST SP 800-61 Rev. 3
Detect (DE): incident response – NIST SP 800-61 Rev. 3

NIST SP 800-61 Rev. 3 DE.CM-09: DE.CM-09 Computing environments monitored for malware, credential attacks, drift, tampering and endpoint health

CSF 2.0 outcome: computing hardware and software, runtime environments and their data are monitored to find potentially adverse events. Priority High. R1: monitor email, web, file sharing, collaboration services and other common attack vectors for malware, phishing, data leaks, exfiltration and other adverse events. R2: monitor authentication attempts to identify attacks on credentials and unauthorized credential use. R3: monitor software and hardware configurations for deviations from security baselines. R4: monitor hardware and software, including security protection mechanisms, for tampering, failure or compromise. R5: monitor endpoints for cyber health issues (missing patches, malware infections, unauthorized software) and redirect unhealthy endpoints to a remediation environment before access is authorized.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Detect (DE): incident response – NIST SP 800-61 Rev. 3

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.