We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

NIST CSF 2.0 · Function 4 of 6

Detect (DE): what it demands and how it is evidenced

Two categories with one question behind them: would you know? Continuous monitoring across networks, endpoints, personnel activity and services — and the analysis discipline that turns anomalies into declared incidents fast enough to matter.

Reviewed by Tanya Kumari, Director — compliance assessment & certification readiness · Part of the CSF 2.0 series · CSF is voluntary guidance — we build profiles, not certificates

The categories inside Detect

DE.CM
Continuous monitoring

Networks, computing environments, personnel activity and external service providers monitored to find adverse events — coverage matched to the asset inventory.

DE.AE
Adverse event analysis

Anomalies analysed, correlated across sources, impact estimated, incidents declared against defined criteria — the pipeline from alert to declaration.

Category identifiers reference NIST CSF 2.0 (26 February 2024) — nist.gov/cyberframework.

Where profiles fall short

Monitoring the network, missing the SaaS

DE.CM in 2.0 explicitly includes external service providers; audit logs from critical SaaS left uncollected is the modern blind spot.

No incident-declaration criteria

DE.AE expects defined thresholds for when an anomaly becomes an incident; without them, response starts late and inconsistently.

Alert fatigue as steady state

A queue with thousands of unreviewed alerts is documentation of detection NOT operating — tuning records are part of the evidence.

Evidence that holds up

  • Monitoring coverage map reconciled against asset inventory (DE.CM)
  • SaaS/provider log ingestion evidence
  • Correlation/analysis workflow with sampled investigations (DE.AE)
  • Incident-declaration criteria and examples of their use
  • Tuning and false-positive reduction records

Detect FAQ

What does CSF 2.0 expect us to monitor?

DE.CM spans networks and network services, computing environments (endpoints, cloud), personnel activity and external service providers — scope driven by your asset inventory and risk assessment.

When does an anomaly become an incident?

When it meets the criteria your organisation defined under DE.AE — severity thresholds, affected assets, confidence. Defining those criteria in advance is itself the expectation.

Do we need a 24×7 SOC?

CSF states outcomes, not staffing models — the test is whether adverse events are detected and analysed in time to limit impact, whether by internal SOC, MDR provider or hybrid.

Protect (PR)Respond (RS)

Your CSF 2.0 profile, built properly

Current and target profiles, gap analysis, and a prioritised roadmap that maps onto the ISO 27001, SOC 2 or SEBI CSCRF work you may already owe — kept current on SigmaTrust.