Anomaly Detection
What is Anomaly Detection?
The identification of patterns in data that deviate from expected behavior, used in security to detect intrusions, fraud, and other threats.
Terms that appear alongside anomaly detection
Each of these is named in at least one of the same controls as anomaly detection. The number is how many controls name both.
- audit 10 shared controls
- authentication 7 shared controls
- nist 7 shared controls
- integrity 7 shared controls
- owasp 6 shared controls
- access control 4 shared controls
- incident response 4 shared controls
- threat intelligence 4 shared controls
Frameworks that govern anomaly detection
What the standards actually require on anomaly detection
Requirements naming anomaly detection across 6 standards, quoted from the control text.
Detect is the third of five functional elements per MSC-FAL.1/Circ.3/Rev.2. Activities include: (1) Anomaly Detection - behavioural baselines for OT systems (bridge equipment patterns + engine room SCADA + propulsion + cargo) + network anomaly detection (deep...
IMO-MSC-FAL-Detect-AnomalyDetection-OT-IT-Monitoring-Reporting-BridgeAlarms · IMO MSC-FAL Detect Function - Anomaly Detection + OT and IT System Monitoring + Bridge Alarms + Log Aggregation + Incident Reporting Channels + Crew Observation →Implement OT audit + monitoring + anomaly detection per NIST SP 800-82 Rev 3 Chapter 6 (Security Architecture) + Chapter 7. OT audit and logging must (a) capture host audit events from OT workstations + engineering workstations + HMI + historian + AD + identit...
NISTSP82-6 · OT Audit, Monitoring, Anomaly Detection, and OT-Specific SOC →Operate log analysis per NIST SP 800-92 Chapter 5 (Operational Processes) + Section 5.12 (Performing Log Analysis). Correlation and detection rules per Section 5.12.1: implement correlation rules combining signals across sources (authentication + endpoint + ne...
NISTSP92-5 · Log Analysis: Correlation, Baselining, Anomaly Detection, Alerting, Manual Review →Detect anomalous telemetry, attitude changes and command sequences that could indicate cyber compromise of a spacecraft.
SISAC-09 · On-Orbit Anomaly Detection →Logging, monitoring, anomaly detection, and EDR with documented coverage and tuning.
FFIEC-CAT-CC-3 · Cybersecurity Controls - Detective Controls →Identity and Access Management (IAM) is a critical control area per FSA Cybersecurity Guidelines + intersects with FISC Security Guidelines + Japan Banking Customer Authentication Standards + APPI access control.
JP-FSA-CYB-Identity-Access-Management-Privileged-Access-MFA-Zero-Trust-Just-In-Time-Banking-Customer-Authentication · Japan FSA Cybersecurity Identity and Access Management + Privileged Access + MFA + Zero Trust + Just-In-Time + Banking Customer Authentication + Risk-Based Authentication + Out-of-Band + Biometric + FIDO2 + Internet Banking Security →Questions people ask about anomaly detection
What is Anomaly Detection?
Why is Anomaly Detection important for compliance?
Which compliance frameworks address Anomaly Detection?
Where can I learn more about Anomaly Detection?
See how Anomaly Detection applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.