DE 11 subcategories · 2 categories

NIST CSF 2.0 Detect (DE)

Detect covers continuous monitoring and adverse event analysis. These outcomes are assessed on coverage and timeliness together: monitoring that watches only part of the environment, or that generates alerts nobody triages, does not achieve the outcome regardless of the tooling behind it.

DE.CM — Continuous Monitoring

DE.CM-01 Network monitoring
Networks and network services are monitored to find potentially adverse events.
DE.CM-02 Physical environment monitoring
The physical environment is monitored to find potentially adverse events.
DE.CM-03 Personnel activity and technology usage monitoring
Personnel activity and technology usage are monitored to find potentially adverse events.
DE.CM-06 External provider activity monitoring
External service provider activities and services are monitored to find potentially adverse events.
DE.CM-09 Computing hardware, software and services monitoring
Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events.

DE.AE — Adverse Event Analysis

DE.AE-02 Event analysis for indicators
Potentially adverse events are analyzed to better understand associated activities.
DE.AE-03 Event correlation across sources
Information is correlated from multiple sources.
DE.AE-04 Event impact and scope estimation
The estimated impact and scope of adverse events are understood.
DE.AE-06 Event information provided to stakeholders
Information on adverse events is provided to authorized staff and tools.
DE.AE-07 Threat intel enrichment of analysis
Cyber threat intelligence and other contextual information are integrated into the analysis.
DE.AE-08 Incident declaration criteria
Incidents are declared when adverse events meet the defined incident criteria.

Other CSF 2.0 functions

GV ID PR RS RC
Crosswalk to ISO 27001 & SOC 2 →
Map these outcomes across frameworks in the Control Mapper.
Search all 106 subcategories →
Filter the CSF 2.0 Core by keyword, function or category.

Frequently asked questions

How many subcategories are in the NIST CSF Detect function?

Detect (DE) contains 11 subcategories across 2 categories. CSF 2.0 defines 106 subcategories in total across six functions: Govern, Identify, Protect, Detect, Respond and Recover.

Is the Detect function mandatory?

No. CSF 2.0 is a voluntary framework of outcomes and there is no certification against it. Its outcomes become binding only through a contract, a regulator that references CSF, or your own Target Profile. That is the practical difference between CSF and an auditable standard like ISO 27001 or SOC 2.

What changed in the Detect function in CSF 2.0?

CSF 2.0 restructured the Core and renumbered subcategories, so DE identifiers do not map one-to-one to CSF 1.1. If you are transitioning a profile, re-assess against the 2.0 Core rather than renaming your existing entries.