Adverse Event Analysis (DE.AE)
Anomalies, indicators of compromise, and other potentially adverse events are analyzed to characterize the events and detect cybersecurity incidents
Subcategories
DE.AE-01:
A baseline of network operations and expected data flows for users and systems is established and managed
[Withdrawn: Incorporated into ID.AM-03]
DE.AE-02
Potentially adverse events are analyzed to better understand associated activities
DE.AE-03
Information is correlated from multiple sources
DE.AE-04
Malicious code is detected
[Withdrawn: Incorporated into DE.CM-01, DE.CM-09]
DE.AE-05
Incident alert thresholds are established
[Withdrawn: Moved to DE.AE-08]
DE.AE-06
Information on adverse events is provided to authorized staff and tools
DE.AE-07
Cyber threat intelligence and other contextual information are integrated into the analysis
DE.AE-08
Incidents are declared when adverse events meet the defined incident criteria