NIST CSF DE.AE - Adverse Event Analysis
Analyze anomalies and potentially adverse events by establishing behavioral baselines, correlating information from multiple sources, estimating impact, integrating threat intelligence, and declaring incidents based on defined criteria
Where this comes from
Provision: DE.AE - Adverse Event Analysis
Instrument: NIST Cybersecurity Framework 2.0 (February 2024)
Citation: NIST Cybersecurity Framework 2.0, February 26, 2024, Section DE.AE (Adverse Event Analysis), Sub-categories DE.AE-01 through DE.AE-08
Text version: CSF 2.0
Who it applies to
It applies when all of these are true:
- Data categories collected — any answer
What engineering work it implies
- Compliance Audit Logging SystemCovers part of it
Implement comprehensive audit logging for regulatory compliance with tamper-evident records.
Sample acceptance criteria Landfall generates for this obligation:
- Process is documented and accessible
- Process steps are implemented in system
- Process outcomes are recorded
- Process can be audited
- Test: a full walkthrough of the process completes end-to-end
Evidence an auditor expects
- Technical controlTechnical audit
Anomaly detection for child accounts
Monitoring for unusual activity on children's accounts
Questions people ask
- Does NIST CSF DE.AE - Adverse Event Analysis apply to my service?
- It applies when Data categories collected — any answer.
- From when does this apply?
- NIST CSF DE.AE - Adverse Event Analysis applies from 26 February 2024. Its current status is: in force.
- What evidence does an auditor expect?
- Anomaly detection for child accounts.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.