April 16, 2018
Function
Cybersecurity Framework
Version 1.1
Category
Subcategory
Informative References
the effectiveness of protective
measures.
DE.CM-2: The physical environment is
monitored to detect potential cybersecurity
events
COBIT 5 DSS01.04, DSS01.05
ISA 62443-2-1:2009 4.3.3.3.8
ISO/IEC 27001:2013 A.11.1.1, A.11.1.2
NIST SP 800-53 Rev. 4 CA-7, PE-3, PE-6, PE-20
DE.CM-3: Personnel activity is monitored
to detect potential cybersecurity events
CIS CSC 5, 7, 14, 16
COBIT 5 DSS05.07
ISA 62443-3-3:2013 SR 6.2
ISO/IEC 27001:2013 A.12.4.1, A.12.4.3
NIST SP 800-53 Rev. 4 AC-2, AU-12, AU-13,
CA-7, CM-10, CM-11
DE.CM-4: Malicious code is detected
CIS CSC 4, 7, 8, 12
COBIT 5 DSS05.01
ISA 62443-2-1:2009 4.3.4.3.8
ISA 62443-3-3:2013 SR 3.2
ISO/IEC 27001:2013 A.12.2.1
NIST SP 800-53 Rev. 4 SI-3, SI-8
DE.CM-5: Unauthorized mobile code is
detected
CIS CSC 7, 8
COBIT 5 DSS05.01
ISA 62443-3-3:2013 SR 2.4
ISO/IEC 27001:2013 A.12.5.1, A.12.6.2
NIST SP 800-53 Rev. 4 SC-18, SI-4, SC-44
DE.CM-6: External service provider
activity is monitored to detect potential
cybersecurity events
COBIT 5 APO07.06, APO10.05
ISO/IEC 27001:2013 A.14.2.7, A.15.2.1
NIST SP 800-53 Rev. 4 CA-7, PS-7, SA-4, SA-9,
SI-4
DE.CM-7: Monitoring for unauthorized
personnel, connections, devices, and
software is performed
CIS CSC 1, 2, 3, 5, 9, 12, 13, 15, 16
COBIT 5 DSS05.02, DSS05.05
ISO/IEC 27001:2013 A.12.4.1, A.14.2.7, A.15.2.1
NIST SP 800-53 Rev. 4 AU-12, CA-7, CM-3,
CM-8, PE-3, PE-6, PE-20, SI-4
DE.CM-8: Vulnerability scans are
performed
CIS CSC 4, 20
This publication is available free of charge from: https://doi.org/10.6028/NIST.CSWP.04162018
39