Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events.
Also written as DE-CM-09, DE.CM-9, CSF 2.0 DE.CM-09, NIST CSF DE.CM.
DE.CM-09 is one of 11 subcategories in the Detect (DE) function, under the Continuous Monitoring category (DE.CM). The Core states: “Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events.” Detect outcomes are assessed on coverage and timeliness together — a monitoring capability that only watches part of the environment, or that nobody reviews, does not achieve the outcome regardless of the tooling in place.
To demonstrate this outcome in an assessment or audit, gather artefacts such as:
DE.CM-09 corresponds to the following ISO 27001:2022 Annex A control(s): A.8.1, A.8.7, A.8.12, A.8.16. Evidence collected for one framework typically supports the other.
No. CSF 2.0 is a voluntary framework of outcomes rather than a set of requirements, and there is no certification against it. DE.CM-09 becomes binding only when something else makes it so — a contract, a regulator that references CSF, or your own Target Profile. That is the practical difference between CSF and an auditable standard like ISO 27001 or SOC 2.
Through profiles rather than pass/fail testing. You record how fully the outcome is achieved today in a Current Profile, state where it needs to be in a Target Profile, and the gap between them becomes your action plan. Implementation Tiers (Partial, Risk Informed, Repeatable, Adaptive) describe how rigorous your governance around the outcome is, not whether you have met it.
The Detect function is normally owned by the security or IT function, but DE.CM-09 still needs a specific named owner. Assessors treat an outcome with no owner as not achieved regardless of the tooling behind it, so record ownership in your profile alongside the assessment.
Yes — DE.CM-09 corresponds to ISO 27001:2022 Annex A control(s) A.8.1, A.8.7, A.8.12, A.8.16. Evidence collected for one framework typically supports the other, so a single control library can serve both.