DE.CM-01: Networks and network services are monitored to find potentially adverse events
Threats Addressed:
Previous Version:
- NIST Cybersecurity Framework v1.1:
- DE.CM-1: The network is monitored to detect potential cybersecurity events
Incorporates the following subcategorys from the previous version of the framework: DE.CM-1: The network is monitored to detect potential cybersecurity events, DE.CM-4: Malicious code is detected, DE.CM-5: Unauthorized mobile code is detected, DE.CM-7: Monitoring for unauthorized personnel, connections, devices, and software is performed.
Description
[csf.tools Note: Subcategories do not have detailed descriptions. However NIST has provided the following implementation examples.]
Implementation Examples
Ex1: Monitor DNS, BGP, and other network services for adverse events
Ex2: Monitor wired and wireless networks for connections from unauthorized endpoints
Ex3: Monitor facilities for unauthorized or rogue wireless networks
Ex4: Compare actual network flows against baselines to detect deviations
Ex5: Monitor network communications to identify changes in security postures for zero trust purposes
1st: 1st Party Risk
Related Controls
NIST Special Publication 800-53 Revision 5.2.0
AC-2: Account Management
Define and document the types of accounts allowed and specifically prohibited for use within the system; Assign account managers; Require [Assignment: organization-defined prerequisites and criteria] for group and role membership; Specify: Authorized users of the system; Group and role membership; and Access authorizations (i.e., privileges) and [Assignment: organization-defined attributes (as required)] for each account; Require…
AU-12: Audit Record Generation
Provide audit record generation capability for the event types the system is capable of auditing as defined in [AU-2a](#au-2_smt.a) on [Assignment: organization-defined system components]; Allow [Assignment: organization-defined personnel or roles] to select the event types that are to be logged by specific components of the system; and Generate audit records for the event types defined…
CA-7: Continuous Monitoring
Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitoring strategy that includes: Establishing the following system-level metrics to be monitored: [Assignment: organization-defined system-level metrics]; Establishing [Assignment: organization-defined frequencies] for monitoring and [Assignment: organization-defined frequencies] for assessment of control effectiveness; Ongoing control assessments in accordance with the continuous…
CM-3: Configuration Change Control
Determine and document the types of changes to the system that are configuration-controlled; Review proposed configuration-controlled changes to the system and approve or disapprove such changes with explicit consideration for security and privacy impact analyses; Document configuration change decisions associated with the system; Implement approved configuration-controlled changes to the system; Retain records of configuration-controlled changes…
SC-5: Denial-of-service Protection
[Assignment: protect against, limit] the effects of the following types of denial-of-service events: [Assignment: organization-defined types of denial-of-service events] ; and Employ the following controls to achieve the denial-of-service objective: [Assignment: organization-defined controls by type of denial-of-service event].
SC-7: Boundary Protection
Monitor and control communications at the external managed interfaces to the system and at key internal managed interfaces within the system; Implement subnetworks for publicly accessible system components that are [Assignment: physically, logically] separated from internal organizational networks; and Connect to external networks or systems only through managed interfaces consisting of boundary protection devices arranged…
SI-4: System Monitoring
Monitor the system to detect: Attacks and indicators of potential attacks in accordance with the following monitoring objectives: [Assignment: organization-defined monitoring objectives] ; and Unauthorized local, network, and remote connections; Identify unauthorized use of the system through the following techniques and methods: [Assignment: organization-defined techniques and methods]; Invoke internal monitoring capabilities or deploy monitoring devices:…
NIST SP 800-171 Revision 3.0
03.01.01: Account Management
Define the types of system accounts allowed and prohibited. Create, enable, modify, disable, and remove system accounts in accordance with policy, procedures, prerequisites, and criteria. Specify: Authorized users of the system, Group and role membership, and Access authorizations (i.e., privileges) for each account. Authorize access to the system based on: A valid access authorization and…
03.03.03: Audit Record Generation
Generate audit records for the selected event types and audit record content specified in 03.03.01 and 03.03.02. Retain audit records for a time period consistent with the records retention policy.
03.04.03: Configuration Change Control
Define the types of changes to the system that are configuration-controlled. Review proposed configuration-controlled changes to the system, and approve or disapprove such changes with explicit consideration for security impacts. Implement and document approved configuration-controlled changes to the system. Monitor and review activities associated with configuration-controlled changes to the system.
03.12.03: Continuous Monitoring
Develop and implement a system-level continuous monitoring strategy that includes ongoing monitoring and security assessments.
03.13.01: Boundary Protection
Monitor and control communications at external managed interfaces to the system and key internal managed interfaces within the system. Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks. Connect to external systems only through managed interfaces that consist of boundary protection devices arranged in accordance with an organizational…
03.13.06: Network Communications — Deny by Default — Allow by Exception
Deny network communications traffic by default, and allow network communications traffic by exception.
03.14.06: System Monitoring
Monitor the system to detect: Attacks and indicators of potential attacks and Unauthorized connections. Identify unauthorized use of the system. Monitor inbound and outbound communications traffic to detect unusual or unauthorized activities or conditions.
Cloud Controls Matrix v4.0
IVS-03: Network Security
Monitor, encrypt and restrict communications between environments to only authenticated and authorized connections, as justified by the business. Review these configurations at least annually, and support them by a documented justification of all allowed services, protocols, ports, and compensating controls.
IVS-09: Network Defense
Define, implement and evaluate processes, procedures and defense-in-depth techniques for protection, detection, and timely response to network-based attacks.
LOG-01: Logging and Monitoring Policy and Procedures
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for logging and monitoring. Review and update the policies and procedures at least annually.
LOG-03: Security Monitoring and Alerting
Identify and monitor security-related events within applications and the underlying infrastructure. Define and implement a system to generate alerts to responsible stakeholders based on such events and corresponding metrics.
LOG-05: Audit Logs Monitoring and Response
Monitor security audit logs to detect activity outside of typical or expected patterns. Establish and follow a defined process to review and take appropriate and timely actions on detected anomalies.
LOG-08: Log Records
Generate audit records containing relevant security information.
TVM-02: Malware Protection Policy and Procedures
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures to protect against malware on managed assets. Review and update the policies and procedures at least annually.
TVM-10: Vulnerability Management Metrics
Establish, monitor and report metrics for vulnerability identification and remediation at defined intervals.
UEM-10: Software Firewall
Configure managed endpoints with properly configured software firewalls.
Critical Security Controls Version 8.1
13.1: Centralize Security Event Alerting
Centralize security event alerting across enterprise assets for log correlation and analysis. Best practice implementation requires the use of a SIEM, which includes vendor-defined event correlation alerts. A log analytics platform configured with security-relevant correlation alerts also satisfies this Safeguard.