DE.CM-09: Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
Threats Addressed:
Subcategory is new to this version of the framework and incorporates the following items from the previous version: PR.DS-6: Integrity checking mechanisms are used to verify software, firmware, and information integrity, PR.DS-8: Integrity checking mechanisms are used to verify hardware integrity, DE.CM-4: Malicious code is detected, DE.CM-5: Unauthorized mobile code is detected, DE.CM-7: Monitoring for unauthorized personnel, connections, devices, and software is performed.
Description
[csf.tools Note: Subcategories do not have detailed descriptions. However NIST has provided the following implementation examples.]
Implementation Examples
Ex1: Monitor email, web, file sharing, collaboration services, and other common attack vectors to detect malware, phishing, data leaks and exfiltration, and other adverse events
Ex2: Monitor authentication attempts to identify attacks against credentials and unauthorized credential reuse
Ex3: Monitor software configurations for deviations from security baselines
Ex4: Monitor hardware and software for signs of tampering
Ex5: Use technologies with a presence on endpoints to detect cyber health issues (e.g., missing patches, malware infections, unauthorized software), and redirect the endpoints to a remediation environment before access is authorized
1st: 1st Party Risk