Skip to main content

๐Ÿ’ผ Anomalies and Events (DE.AE)

  • Contextual name: ๐Ÿ’ผ Anomalies and Events (DE.AE)
  • ID: /frameworks/nist-csf-v1.1/de-ae
  • Located in: ๐Ÿ’ผ NIST CSF v1.1

Descriptionโ€‹

Anomalous activity is detected and the potential impact of events is understood.

Similarโ€‹

  • Internal
    • ID: dec-b-18b8c0de

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ DE.AE-1: A baseline of network operations and expected data flows for users and systems is established and managed1011
๐Ÿ’ผ DE.AE-2: Detected events are analyzed to understand attack targets and methods1922
๐Ÿ’ผ DE.AE-3: Event data are collected and correlated from multiple sources and sensors1922
๐Ÿ’ผ DE.AE-4: Impact of events is determined1414
๐Ÿ’ผ DE.AE-5: Incident alert thresholds are established