Endpoint Detection and Response
What is Endpoint Detection and Response?
Security solutions that continuously monitor endpoint devices to detect, investigate, and respond to cyber threats using behavioral analysis and automated response.
Terms that appear alongside endpoint detection and response
Each of these is named in at least one of the same controls as endpoint detection and response. The number is how many controls name both.
- security operations 3 shared controls
- malware 3 shared controls
- cybersecurity 3 shared controls
- mitre 2 shared controls
- security monitoring 2 shared controls
- threat intelligence 2 shared controls
- user and entity behavior analytics 2 shared controls
- security information and event management siem 2 shared controls
Frameworks that govern endpoint detection and response
What the standards actually require on endpoint detection and response
Requirements naming endpoint detection and response across 6 standards, quoted from the control text.
Deploy Microsoft Defender for Endpoint on Azure VMs with continuous monitoring, alerting, and automated response.
ES-1 · Use Endpoint Detection and Response (EDR) →Endpoint detection and response software on all computers for centralised analysis and reporting of threat indicators.
ASD37-30 · Endpoint detection and response (Very Good) →Per EO 14028 + OMB M-22-01: Endpoint Detection and Response Deployment across federal agencies + integration with CISA.
USEO14028-4 · Endpoint Detection and Response (EDR) →Implement risk-based controls including monitoring of authorized user activity and detection of unauthorized access or tampering, malware protection, annual cybersecurity awareness training including social engineering.
§500.14 · Monitoring and Training →Deploy a host-based intrusion prevention solution on enterprise assets, where appropriate and/or supported. Example implementations include use of an Endpoint Detection and Response (EDR) client or host-based IPS agent.
CIS-13.7 · Deploy a Host-Based Intrusion Prevention Solution →Configure endpoint protection (antivirus / endpoint detection and response) in accordance with the applicable STIG.
STIG-SRG-EPP · Endpoint protection (antivirus/EDR) STIG →Questions people ask about endpoint detection and response
What is Endpoint Detection and Response?
Why is Endpoint Detection and Response important for compliance?
Which compliance frameworks address Endpoint Detection and Response?
Where can I learn more about Endpoint Detection and Response?
See how Endpoint Detection and Response applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.