SANS Incident Handler's Handbook and PICERL Methodology
Phase 2 - Identification

SANS Incident Handler's Handbook and PICERL Methodology PICERL-I1: Monitoring and Detection

Monitor IT systems and detect deviations from normal operations to identify actual security incidents

Other controls in Phase 2 - Identification

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.