Skip to main content

πŸ’Ό DE.CM-02: The physical environment is monitored to find potentially adverse events

  • Contextual name: πŸ’Ό DE.CM-02: The physical environment is monitored to find potentially adverse events
  • ID: /frameworks/nist-csf-v2.0/de-cm/02
  • Located in: πŸ’Ό Continuous Monitoring (DE.CM)

Description​

  1. Monitor logs from physical access control systems (e.g., badge readers) to find unusual access patterns (e.g., deviations from the norm) and failed access attempts
  2. Review and monitor physical access records (e.g., from visitor registration, sign-in sheets)
  3. Monitor physical access controls (e.g., locks, latches, hinge pins, alarms) for signs of tampering
  4. Monitor the physical environment using alarm systems, cameras, and security guards

Similar​

  • Sections
    • /frameworks/nist-csf-v1.1/de-cm/02
    • /frameworks/nist-sp-800-53-r5/ca/07
    • /frameworks/nist-sp-800-53-r5/pe/03
    • /frameworks/nist-sp-800-53-r5/pe/06
    • /frameworks/nist-sp-800-53-r5/pe/20

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό DE.CM-2: The physical environment is monitored to detect potential cybersecurity events
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CA-7 Continuous Monitoring68
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό PE-3 Physical Access Control8
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό PE-6 Monitoring Physical Access4
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό PE-20 Asset Monitoring and Tracking

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (8)​

PolicyLogic CountFlags
πŸ“ AWS Account Multi-Region CloudTrail is not enabled 🟒1🟒 x6
πŸ“ AWS API Gateway API Access Logging in CloudWatch is not enabled 🟒1🟠 x1, 🟒 x5
πŸ“ AWS API Gateway API Execution Logging in CloudWatch is not enabled 🟒1🟒 x6
πŸ“ AWS API Gateway REST API Stage X-Ray Tracing is not enabled 🟒1🟒 x6
πŸ“ AWS CloudTrail S3 Bucket Access Logging is not enabled. 🟒1🟒 x6
πŸ“ AWS EC2 Auto Scaling Group behind ELB doesn't use ELB health check 🟒1🟒 x6
πŸ“ AWS S3 Bucket Server Access Logging is not enabled 🟒1🟒 x6
πŸ“ AWS VPC Flow Logs are not enabled 🟒1🟠 x1, 🟒 x5