[Withdrawn: Incorporated into ID.AM-03]
Anomalies, indicators of compromise, and other potentially adverse events are analyzed to characterize the events and detect cybersecurity incidents
| Citation | DE.AE |
|---|---|
| Clé de plateforme | arcate:compliance:requirements/nist-csf/2.0/DE.AE |
| Emplacement dans la source | row 169 of sheet 'CSF 2.0' |
| Publié par | NIST |
Exigences filles
Potentially adverse events are analyzed to better understand associated activities
Information is correlated from multiple sources
The estimated impact and scope of adverse events are understood
[Withdrawn: Moved to DE.AE-08]
Information on adverse events is provided to authorized staff and tools
Cyber threat intelligence and other contextual information are integrated into the analysis
Incidents are declared when adverse events meet the defined incident criteria