DE.AE: Anomalies and Events
Next Version:
- NIST Cybersecurity Framework v2.0:
- DE.AE: Adverse Event Analysis
Description
Anomalous activity is detected and the potential impact of events is understood.
Framework Subcategories
DE.AE-1: A baseline of network operations and expected data flows for users and systems is established and managed
[csf.tools Note: Subcategories do not have detailed descriptions.]
DE.AE-2: Detected events are analyzed to understand attack targets and methods
[csf.tools Note: Subcategories do not have detailed descriptions.]
DE.AE-3: Event data are collected and correlated from multiple sources and sensors
[csf.tools Note: Subcategories do not have detailed descriptions.]
DE.AE-4: Impact of events is determined
[csf.tools Note: Subcategories do not have detailed descriptions.]
DE.AE-5: Incident alert thresholds are established
[csf.tools Note: Subcategories do not have detailed descriptions.]