DE.AE: Adverse Event Analysis
Previous Version:
- NIST Cybersecurity Framework v1.1:
- DE.AE: Anomalies and Events
Incorporates the following categorys from the previous version of the framework: DE.AE: Anomalies and Events, DE.DP-2: Detection activities comply with all applicable requirements.
Description
Anomalies, indicators of compromise, and other potentially adverse events are analyzed to characterize the events and detect cybersecurity incidents
Framework Subcategories
DE.AE-02: Potentially adverse events are analyzed to better understand associated activities
[csf.tools Note: Subcategories do not have detailed descriptions.]
DE.AE-03: Information is correlated from multiple sources
[csf.tools Note: Subcategories do not have detailed descriptions.]
DE.AE-04: The estimated impact and scope of adverse events are understood
[csf.tools Note: Subcategories do not have detailed descriptions.]
DE.AE-06: Information on adverse events is provided to authorized staff and tools
[csf.tools Note: Subcategories do not have detailed descriptions.]
DE.AE-07: Cyber threat intelligence and other contextual information are integrated into the analysis
[csf.tools Note: Subcategories do not have detailed descriptions.]
DE.AE-08: Incidents are declared when adverse events meet the defined incident criteria
[csf.tools Note: Subcategories do not have detailed descriptions.]