Skip to content

Endpoint Detection and Response

What is Endpoint Detection and Response?

Security solutions that continuously monitor endpoint devices to detect, investigate, and respond to cyber threats using behavioral analysis and automated response.

Information Security

Each of these is named in at least one of the same controls as endpoint detection and response. The number is how many controls name both.

What the standards actually require on endpoint detection and response

Requirements naming endpoint detection and response across 6 standards, quoted from the control text.

Deploy Microsoft Defender for Endpoint on Azure VMs with continuous monitoring, alerting, and automated response.

ES-1 · Use Endpoint Detection and Response (EDR)

Endpoint detection and response software on all computers for centralised analysis and reporting of threat indicators.

ASD37-30 · Endpoint detection and response (Very Good)

Per EO 14028 + OMB M-22-01: Endpoint Detection and Response Deployment across federal agencies + integration with CISA.

USEO14028-4 · Endpoint Detection and Response (EDR)

Implement risk-based controls including monitoring of authorized user activity and detection of unauthorized access or tampering, malware protection, annual cybersecurity awareness training including social engineering.

§500.14 · Monitoring and Training

Deploy a host-based intrusion prevention solution on enterprise assets, where appropriate and/or supported. Example implementations include use of an Endpoint Detection and Response (EDR) client or host-based IPS agent.

CIS-13.7 · Deploy a Host-Based Intrusion Prevention Solution

Configure endpoint protection (antivirus / endpoint detection and response) in accordance with the applicable STIG.

STIG-SRG-EPP · Endpoint protection (antivirus/EDR) STIG

Questions people ask about endpoint detection and response

What is Endpoint Detection and Response?
Security solutions that continuously monitor endpoint devices to detect, investigate, and respond to cyber threats using behavioral analysis and automated response.
Why is Endpoint Detection and Response important for compliance?
Endpoint Detection and Response is a key concept in Information Security. Understanding endpoint detection and response helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Endpoint Detection and Response?
Endpoint Detection and Response appears in the requirement text of Azure Security Benchmark, ASD Strategies to Mitigate Cyber Security Incidents, US Executive Order 14028 - Improving the Nation's Cybersecurity, NY DFS 23 NYCRR 500, CIS Controls v8. Across these standards we have identified 8 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Endpoint Detection and Response?
Explore our compliance framework pages to see how endpoint detection and response applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Endpoint Detection and Response applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.