# DE — Detect

- **Function ID:** DE

## Subcategories

- [DE.AE-02](/md/csf/DE.AE-02.md) — Potentially adverse events are analyzed to better understand associated activities
- [DE.AE-03](/md/csf/DE.AE-03.md) — Information is correlated from multiple sources
- [DE.AE-04](/md/csf/DE.AE-04.md) — The estimated impact and scope of adverse events are understood
- [DE.AE-06](/md/csf/DE.AE-06.md) — Information on adverse events is provided to authorized staff and tools
- [DE.AE-07](/md/csf/DE.AE-07.md) — Cyber threat intelligence and other contextual information are integrated into the analysis
- [DE.AE-08](/md/csf/DE.AE-08.md) — DE.AE-08
- [DE.CM-01](/md/csf/DE.CM-01.md) — Networks and network services are monitored to find potentially adverse events
- [DE.CM-02](/md/csf/DE.CM-02.md) — The physical environment is monitored to find potentially adverse events
- [DE.CM-03](/md/csf/DE.CM-03.md) — Personnel activity and technology usage are monitored to find potentially adverse events
- [DE.CM-06](/md/csf/DE.CM-06.md) — External service provider activities and services are monitored to find potentially adverse events
- [DE.CM-09](/md/csf/DE.CM-09.md) — DE.CM-09

---

Derived from official NIST publications (NIST SP 800-53 Rev 5 and NIST CSF 2.0). nistcontrols.com is not affiliated with NIST.
