[Withdrawn: Incorporated into ID.AM-08, PR.PS-03]
| Publié par | NIST |
|---|---|
| Version | 2.0 |
| Date de publication | 2024-02-26 |
| Langue | en |
| Exigences | 225 |
| Document source | csf.xlsx |
| Clé de plateforme | arcate:compliance:frameworks/nist-csf/2.0 |
Exigences
[Withdrawn: Incorporated into ID.AM-08, PR.PS-02]
PR.PT
— Protective Technology
[Withdrawn: Incorporated into other Protect Categories]
[Withdrawn: Incorporated into PR.PS-04]
[Withdrawn: Incorporated into PR.DS-01, PR.PS-01]
[Withdrawn: Incorporated into PR.PS-01]
[Withdrawn: Incorporated into PR.AA-06, PR.IR-01]
[Withdrawn: Moved to PR.IR-03]
DE
— DETECT
Possible cybersecurity attacks and compromises are found and analyzed
DE.CM
— Continuous Monitoring
Assets are monitored to find anomalies, indicators of compromise, and other potentially adverse events
Networks and network services are monitored to find potentially adverse events
The physical environment is monitored to find potentially adverse events
Personnel activity and technology usage are monitored to find potentially adverse events
[Withdrawn: Incorporated into DE.CM-01, DE.CM-09]
[Withdrawn: Incorporated into DE.CM-01, DE.CM-09]
External service provider activities and services are monitored to find potentially adverse events
[Withdrawn: Incorporated into DE.CM-01, DE.CM-03, DE.CM-06, DE.CM-09]
[Withdrawn: Incorporated into ID.RA-01]
Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
DE.AE
— Adverse Event Analysis
Anomalies, indicators of compromise, and other potentially adverse events are analyzed to characterize the events and detect cybersecurity incidents
[Withdrawn: Incorporated into ID.AM-03]
Potentially adverse events are analyzed to better understand associated activities
Information is correlated from multiple sources
The estimated impact and scope of adverse events are understood