Detect (DE): what it demands and how it is evidenced
Two categories with one question behind them: would you know? Continuous monitoring across networks, endpoints, personnel activity and services — and the analysis discipline that turns anomalies into declared incidents fast enough to matter.
Reviewed by Tanya Kumari, Director — compliance assessment & certification readiness · Part of the CSF 2.0 series · CSF is voluntary guidance — we build profiles, not certificates
The categories inside Detect
Category identifiers reference NIST CSF 2.0 (26 February 2024) — nist.gov/cyberframework.
Where profiles fall short
DE.CM in 2.0 explicitly includes external service providers; audit logs from critical SaaS left uncollected is the modern blind spot.
DE.AE expects defined thresholds for when an anomaly becomes an incident; without them, response starts late and inconsistently.
A queue with thousands of unreviewed alerts is documentation of detection NOT operating — tuning records are part of the evidence.
Evidence that holds up
- Monitoring coverage map reconciled against asset inventory (DE.CM)
- SaaS/provider log ingestion evidence
- Correlation/analysis workflow with sampled investigations (DE.AE)
- Incident-declaration criteria and examples of their use
- Tuning and false-positive reduction records
Detect FAQ
What does CSF 2.0 expect us to monitor?
DE.CM spans networks and network services, computing environments (endpoints, cloud), personnel activity and external service providers — scope driven by your asset inventory and risk assessment.
When does an anomaly become an incident?
When it meets the criteria your organisation defined under DE.AE — severity thresholds, affected assets, confidence. Defining those criteria in advance is itself the expectation.
Do we need a 24×7 SOC?
CSF states outcomes, not staffing models — the test is whether adverse events are detected and analysed in time to limit impact, whether by internal SOC, MDR provider or hybrid.
Your CSF 2.0 profile, built properly
Current and target profiles, gap analysis, and a prioritised roadmap that maps onto the ISO 27001, SOC 2 or SEBI CSCRF work you may already owe — kept current on SigmaTrust.
