The Detect Function describes activities will help an agency to develop and implement the appropriate safeguards to identify cybersecurity events. These activities will enable timely discovery of potential cybersecurity events to allow for immediate recovery responses.
Anomalies and Events
Detecting anomalous activity in a timely manner and understanding the potential impact.
- Create and manage a baseline of network operations (i.e. a documented reference of the normal everyday working state of the network) and expected data flows (i.e. a representation of the way data should "flow" through an information system, network, or between users) for users and systems.
- Analyze detected cybersecurity events to understand why targets were attacked and the methods used.
- Collect, combine, and compare cybersecurity event data from multiple sources and sensors (e.g. a series of sensors to monitor liquid leaks, temperature and humidity levels, smoke, etc.).
- Determine the impact of cybersecurity events to information systems, the network, and users.
- Establish incident alert thresholds (i.e. the point at which an incident alert is generated).
Security Continuous Monitoring
Monitoring information systems and assets at discrete intervals to identify cybersecurity events and verify the effectiveness of protective measures.
- Monitor the network to detect potential cybersecurity events.
- Monitor the physical environment to detect potential cybersecurity events.
- Monitor personnel activity to detect potential cybersecurity events.
- Detect malicious code (i.e. any code in any part of a software system or script that is intended to cause undesired effects, security breaches, or damage to a system or network (e.g. virus, worm, etc.)) .
- Detect unauthorized mobile code (i.e. any program, application, or content capable of automatically executing or completing an action, without the user directly or knowingly authorizing the action. Malicious code is typically embedded in an email, document, or website).
- Monitor external service provider activity to detect potential cybersecurity events.
- Monitor for unauthorized personnel, connections, devices, and software.
- Perform vulnerability scans.
Detection Processes
Maintaining and testing detection processes and procedures (e.g. using vulnerability scans, intrusion detection and prevention systems, audit monitoring, etc.) to ensure timely and adequate awareness of anomalous events.
- Define roles and responsibilities for detection to ensure accountability.
- Detection activities must comply with all applicable requirements.
- Ensure detection processes are regularly tested.
- Ensure that event detection information (e.g. vulnerability scan results, audit records analysis, etc.) is communicated to appropriate parties.
- Ensure detection processes are continuously improved.