DE.CM-01 DE · Detect · DE.CM Continuous Monitoring

DE.CM-01 — Network monitoring

Networks and network services are monitored to find potentially adverse events.

Also written as DE-CM-01, DE.CM-1, CSF 2.0 DE.CM-01, NIST CSF DE.CM.

What NIST CSF DE.CM-01 means

DE.CM-01 is one of 11 subcategories in the Detect (DE) function, under the Continuous Monitoring category (DE.CM). The Core states: “Networks and network services are monitored to find potentially adverse events.” Detect outcomes are assessed on coverage and timeliness together — a monitoring capability that only watches part of the environment, or that nobody reviews, does not achieve the outcome regardless of the tooling in place.

Evidence that supports DE.CM-01

To demonstrate this outcome in an assessment or audit, gather artefacts such as:

  • Network monitoring / IDS deployment and coverage
  • NetFlow or traffic analysis output
  • Alerts raised from network anomalies with triage records

How to implement DE.CM-01

  1. Establish what normal looks like firstAdverse events are deviations, which presupposes a baseline. Traffic profiles, expected egress destinations and normal service-to-service communication give detection something to measure against. Without a baseline you get volume rather than signal.
  2. Instrument east-west, not only north-southPerimeter monitoring misses lateral movement, which is where an intrusion becomes a breach. Flow logs between internal segments and between cloud workloads are what surface that, and they are commonly missing.
  3. Monitor encrypted traffic by metadataMost traffic is encrypted and inspecting it is often neither practical nor lawful. Destination, volume, timing and certificate metadata still yield strong signals — beaconing and exfiltration patterns are visible without decryption.
  4. Route alerts to a defined responderThe outcome is about finding adverse events, which implies someone finds them. Whether that is a SOC, an MSSP or a named engineer on a rota, the responsibility and schedule need to be recorded.
  5. Document coverage and the gaps you acceptedA network monitoring coverage map — segments, cloud VPCs, remote workers, third-party connections — with declared gaps and rationale is the artefact that makes this outcome assessable.

Common assessment findings for DE.CM-01

What actually gets raised against DE.CM-01, in rough order of how often it comes up:

Assessing DE.CM-01 in a profile

DE.CM-01 is assessed on coverage and timeliness together. Partial coverage that is well understood and declared scores better in practice than broad coverage nobody can describe, because the Current Profile is supposed to reflect reality rather than intent.

ISO 27001 mapping

DE.CM-01 corresponds to the following ISO 27001:2022 Annex A control(s): A.8.16, A.8.20. Evidence collected for one framework typically supports the other.

Map DE.CM-01 to ISO 27001 & SOC 2 →
Crosswalk this subcategory in the Control Mapper & Gap Assessment.
Document the risk →
Record treatment for gaps against DE.CM-01 in the Risk Register.

Other Continuous Monitoring subcategories

DE.CM-02 Physical environment monitoring DE.CM-03 Personnel activity and technology usage monitoring DE.CM-06 External provider activity monitoring DE.CM-09 Computing hardware, software and services monitoring

All 11 Detect subcategories →

Frequently asked questions

Is NIST CSF DE.CM-01 mandatory?

No. CSF 2.0 is a voluntary framework of outcomes rather than a set of requirements, and there is no certification against it. DE.CM-01 becomes binding only when something else makes it so — a contract, a regulator that references CSF, or your own Target Profile. That is the practical difference between CSF and an auditable standard like ISO 27001 or SOC 2.

How is DE.CM-01 assessed?

Through profiles rather than pass/fail testing. You record how fully the outcome is achieved today in a Current Profile, state where it needs to be in a Target Profile, and the gap between them becomes your action plan. Implementation Tiers (Partial, Risk Informed, Repeatable, Adaptive) describe how rigorous your governance around the outcome is, not whether you have met it.

Who owns DE.CM-01?

The Detect function is normally owned by the security or IT function, but DE.CM-01 still needs a specific named owner. Assessors treat an outcome with no owner as not achieved regardless of the tooling behind it, so record ownership in your profile alongside the assessment.

Does NIST CSF DE.CM-01 map to ISO 27001?

Yes — DE.CM-01 corresponds to ISO 27001:2022 Annex A control(s) A.8.16, A.8.20. Evidence collected for one framework typically supports the other, so a single control library can serve both.

What are the most common audit findings for DE.CM-01?

Perimeter monitoring only, with no visibility of internal or cloud-to-cloud traffic. Remote workers outside the monitored network entirely, which for a distributed organisation is most of the traffic.