DE · DETECT

Erkennen

Mögliche Cybersicherheitsangriffe und Kompromittierungen werden zeitnah gefunden und analysiert.

2 Kategorien · 11 Ergebnisziele

DE.CM

Kontinuierliche Überwachung (Continuous Monitoring)

Assets werden überwacht, um Anomalien, Kompromittierungsindikatoren und andere potenziell nachteilige Ereignisse zu finden.

DE.CM-09

Rechen-Hardware und -Software, Laufzeitumgebungen und ihre Daten werden überwacht, um potenziell nachteilige Ereignisse zu finden.

Eigenrisiko

NIST-Originalwortlaut: Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events

Umsetzungsbeispiele (5)
  • Monitor email, web, file sharing, collaboration services, and other common attack vectors to detect malware, phishing, data leaks and exfiltration, and other adverse events
  • Monitor authentication attempts to identify attacks against credentials and unauthorized credential reuse
  • Monitor software configurations for deviations from security baselines
  • Monitor hardware and software for signs of tampering
  • Use technologies with a presence on endpoints to detect cyber health issues (e.g., missing patches, malware infections, unauthorized software), and redirect the endpoints to a remediation environment before access is authorized
DE.CM-01

Netzwerke und Netzwerkdienste werden überwacht, um potenziell nachteilige Ereignisse zu finden.

Eigenrisiko

NIST-Originalwortlaut: Networks and network services are monitored to find potentially adverse events

Umsetzungsbeispiele (5)
  • Monitor DNS, BGP, and other network services for adverse events
  • Monitor wired and wireless networks for connections from unauthorized endpoints
  • Monitor facilities for unauthorized or rogue wireless networks
  • Compare actual network flows against baselines to detect deviations
  • Monitor network communications to identify changes in security postures for zero trust purposes
DE.CM-02

Die physische Umgebung wird überwacht, um potenziell nachteilige Ereignisse zu finden.

Eigenrisiko

NIST-Originalwortlaut: The physical environment is monitored to find potentially adverse events

Umsetzungsbeispiele (4)
  • Monitor logs from physical access control systems (e.g., badge readers) to find unusual access patterns (e.g., deviations from the norm) and failed access attempts
  • Review and monitor physical access records (e.g., from visitor registration, sign-in sheets)
  • Monitor physical access controls (e.g., locks, latches, hinge pins, alarms) for signs of tampering
  • Monitor the physical environment using alarm systems, cameras, and security guards
DE.CM-03

Aktivitäten des Personals und Technologienutzung werden überwacht, um potenziell nachteilige Ereignisse zu finden.

Eigenrisiko

NIST-Originalwortlaut: Personnel activity and technology usage are monitored to find potentially adverse events

Umsetzungsbeispiele (3)
  • Use behavior analytics software to detect anomalous user activity to mitigate insider threats
  • Monitor logs from logical access control systems to find unusual access patterns and failed access attempts
  • Continuously monitor deception technology, including user accounts, for any usage
DE.CM-06

Aktivitäten und Dienste externer Dienstleister werden überwacht, um potenziell nachteilige Ereignisse zu finden.

Drittrisiko

NIST-Originalwortlaut: External service provider activities and services are monitored to find potentially adverse events

Umsetzungsbeispiele (2)
  • Monitor remote and onsite administration and maintenance activities that external providers perform on organizational systems
  • Monitor activity from cloud-based services, internet service providers, and other service providers for deviations from expected behavior
DE.AE

Analyse nachteiliger Ereignisse (Adverse Event Analysis)

Anomalien und potenziell nachteilige Ereignisse werden analysiert, um Ereignisse zu charakterisieren und Vorfälle zu erkennen.

DE.AE-02

Potenziell nachteilige Ereignisse werden analysiert, um die zugehörigen Aktivitäten besser zu verstehen.

Eigenrisiko

NIST-Originalwortlaut: Potentially adverse events are analyzed to better understand associated activities

Umsetzungsbeispiele (4)
  • Use security information and event management (SIEM) or other tools to continuously monitor log events for known malicious and suspicious activity
  • Utilize up-to-date cyber threat intelligence in log analysis tools to improve detection accuracy and characterize threat actors, their methods, and indicators of compromise
  • Regularly conduct manual reviews of log events for technologies that cannot be sufficiently monitored through automation
  • Use log analysis tools to generate reports on their findings
DE.AE-03

Informationen aus mehreren Quellen werden korreliert.

Eigenrisiko

NIST-Originalwortlaut: Information is correlated from multiple sources

Umsetzungsbeispiele (3)
  • Constantly transfer log data generated by other sources to a relatively small number of log servers
  • Use event correlation technology (e.g., SIEM) to collect information captured by multiple sources
  • Utilize cyber threat intelligence to help correlate events among log sources
DE.AE-04

Geschätzte Auswirkung und Umfang nachteiliger Ereignisse werden verstanden.

Eigenrisiko

NIST-Originalwortlaut: The estimated impact and scope of adverse events are understood

Umsetzungsbeispiele (2)
  • Use SIEMs or other tools to estimate impact and scope, and review and refine the estimates
  • A person creates their own estimates of impact and scope
DE.AE-08

Vorfälle werden deklariert, wenn nachteilige Ereignisse die definierten Vorfallkriterien erfüllen.

Eigenrisiko

NIST-Originalwortlaut: Incidents are declared when adverse events meet the defined incident criteria

Umsetzungsbeispiele (2)
  • Apply incident criteria to known and assumed characteristics of activity in order to determine whether an incident should be declared
  • Take known false positives into account when applying incident criteria
DE.AE-06

Informationen über nachteilige Ereignisse werden autorisiertem Personal und Werkzeugen bereitgestellt.

Eigenrisiko

NIST-Originalwortlaut: Information on adverse events is provided to authorized staff and tools

Umsetzungsbeispiele (4)
  • Use cybersecurity software to generate alerts and provide them to the security operations center (SOC), incident responders, and incident response tools
  • Incident responders and other authorized personnel can access log analysis findings at all times
  • Automatically create and assign tickets in the organization's ticketing system when certain types of alerts occur
  • Manually create and assign tickets in the organization's ticketing system when technical staff discover indicators of compromise
DE.AE-07

Cyber-Bedrohungsinformationen und weiterer Kontext werden in die Analyse einbezogen.

Eigenrisiko

NIST-Originalwortlaut: Cyber threat intelligence and other contextual information are integrated into the analysis

Umsetzungsbeispiele (3)
  • Securely provide cyber threat intelligence feeds to detection technologies, processes, and personnel
  • Securely provide information from asset inventories to detection technologies, processes, and personnel
  • Rapidly acquire and analyze vulnerability disclosures for the organization's technologies from suppliers, vendors, and third-party security advisories