Adverse Event Analysis (DE.AE)

Anomalies, indicators of compromise, and other potentially adverse events are analyzed to characterize the events and detect cybersecurity incidents

Subcategories

DE.AE-01:

A baseline of network operations and expected data flows for users and systems is established and managed

[Withdrawn: Incorporated into ID.AM-03]

DE.AE-02

Potentially adverse events are analyzed to better understand associated activities

DE.AE-03

Information is correlated from multiple sources

DE.AE-04

Malicious code is detected

[Withdrawn: Incorporated into DE.CM-01, DE.CM-09]

DE.AE-05

Incident alert thresholds are established

[Withdrawn: Moved to DE.AE-08]

DE.AE-06

Information on adverse events is provided to authorized staff and tools

DE.AE-07

Cyber threat intelligence and other contextual information are integrated into the analysis

DE.AE-08

Incidents are declared when adverse events meet the defined incident criteria