NIST CSF DE.CM - Continuous Monitoring
Continuously monitor networks, physical environments, personnel activity, external providers, computing assets, and security logs to detect anomalies, indicators of compromise, and potentially adverse events
Where this comes from
Provision: DE.CM - Continuous Monitoring
Instrument: NIST Cybersecurity Framework 2.0 (February 2024)
Citation: NIST Cybersecurity Framework 2.0, February 26, 2024, Section DE.CM (Continuous Monitoring), Sub-categories DE.CM-01 through DE.CM-09
Text version: CSF 2.0
Who it applies to
It applies when all of these are true:
- Data categories collected — any answer
- Service collects behavioral data
What engineering work it implies
- Compliance Audit Logging SystemCovers it fully
Implement comprehensive audit logging for regulatory compliance with tamper-evident records.
Sample acceptance criteria Landfall generates for this obligation:
- Networks, endpoints, and the physical environment are monitored for anomalies and indicators of compromise
- Personnel activity and external service-provider activity are monitored in accordance with policy
- Security logs are aggregated (SIEM) and correlated to detect potentially adverse events
- Detections generate alerts routed to responders against defined thresholds
- System handles null/empty input gracefully (no 500 errors)
Questions people ask
- Does NIST CSF DE.CM - Continuous Monitoring apply to my service?
- It applies when Data categories collected — any answer; Service collects behavioral data.
- From when does this apply?
- NIST CSF DE.CM - Continuous Monitoring applies from 26 February 2024. Its current status is: in force.
- What engineering work does this imply?
- Typically: Compliance Audit Logging System.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.