Skip to Content

Europe & ISO

Attack detection across Europe

How ZephSense meets European and international Detection & Response requirements.

Beyond the German BSI SzA, a dense web of NIS2, DORA and national regimes applies across Europe, plus the ISO standards. We defined 23 functional core requirements along the NIST Cybersecurity Framework 2.0, assessed them against ZephSense and mapped them to all relevant frameworks. New: the maturity level shows where the platform responds automatically and relieves the SOC team.

The result in numbers

23

Core requirements (NIST CSF 2.0)

23

Addressed by ZephSense/service

16

Auto-detected & alerted

6

Automated response (active response)

23

Frameworks mapped

17

Met technically by the platform

The maturity level reflects that ZephSense not only detects but responds automatically. The short reporting deadlines (NIS2 24h/72h, DORA 4h, Italy 1h/6h) are in practice only achievable with automation.

Coverage and automation maturity

Each core requirement has two assessments. Coverage shows how ZephSense supports it. The maturity level shows how far automation reaches.

Coverage: Met Met · SOC/MDR SOC/MDR · Supported Supported · Operator Operator
Maturity: 1 · Detected · 2 · Alerted · 3 · Auto-response

  • 1 · Detected – the relevant data is captured and made visible automatically.
  • 2 · Alerted – the platform detects on its own and alerts automatically.
  • 3 · Auto-response – the platform responds automatically (containment), controllable per network, with human-in-the-loop where appropriate.

The Detection & Response core catalogue

23 functional core requirements along NIST CSF 2.0, each mapped to a ZephSense capability.

IDCore requirementNIST CSFCoverageMaturity
Govern
GV-1Dokumentierte Detection-&-Response-Leitlinie und Rollen
Ein formal dokumentierter Prozess fuer Erkennung und Reaktion mit klaren Rollen, Verantwortlichkeiten, Eskalations- und Kommunikationswegen ueber den gesamten Vorfallslebenszyklus.
▸ takes off the SOC: initial response and incident containment
GV.RR-02 / GV.PO-01Supported1 · Detected
Protect (Logging)
PR-1Systematische Erfassung sicherheitsrelevanter Ereignisse
Risikobasiertes Erzeugen und Sammeln sicherheitsrelevanter Protokolldaten aus Netzwerk, Systemen, Endpoints, Authentifizierung und privilegierten Zugriffen.
▸ takes off the SOC: round-the-clock network monitoring
PR.PS-04 / DE.CMMet1 · Detected
PR-2Zentrale Sammlung, Normalisierung und Aufbereitung
Zusammenfuehren der Protokolldaten an zentraler Stelle mit Filterung, Normalisierung (einheitliches Zeitformat) und Aggregation, damit sie auswertbar werden.
▸ takes off the SOC: collecting and preparing the log data
DE.AE-03Met1 · Detected
PR-3Integritaets- und Zugriffsschutz der Protokolldaten
Manipulationsgeschuetzte, integritaetsgesicherte Ablage der Protokolle mit rollenbasiertem Zugriffsschutz, damit sie als Nachweis belastbar bleiben.
▸ takes off the SOC: collecting and preparing the log data
PR.PS-04 / PR.AAMet1 · Detected
PR-4Zeitsynchronisation der Datenquellen
Einheitliche, synchronisierte Zeitbasis fuer die Korrelation ueber verschiedene Quellen. (Die Quell-Uhren stellt der Betreiber; die Plattform vereinheitlicht eingehende Zeitformate.)
▸ takes off the SOC: aggregating and correlating thousands of single alerts
PR.PS-04Supported1 · Detected
PR-5Aufbewahrung nach definierten Fristen
Konfigurierbare Aufbewahrung und Loeschung der Protokolldaten entsprechend den rechtlichen und regulatorischen Fristen.
▸ takes off the SOC: collecting and preparing the log data
PR.PS-04Met1 · Detected
Detect (Monitoring)
DE-1Kontinuierliche Netzwerkueberwachung
Fortlaufende, moeglichst automatisierte Ueberwachung des Netzwerkverkehrs an internen und externen Uebergaengen (Flow-/Protokollanalyse, DNS).
▸ takes off the SOC: reviewing and alerting on security events
DE.CM-01Met2 · Alerted
DE-2Kontinuierliche Endpoint- und Systemueberwachung
Fortlaufende Ueberwachung von Servern und Endpoints auf sicherheitsrelevante Aktivitaeten und Prozessverhalten.
▸ takes off the SOC: reviewing and alerting on security events
DE.CM-01 / DE.CM-03Met2 · Alerted
DE-3Ueberwachung der Wirksamkeit der Sicherheitsmechanismen
Laufende Kontrolle, ob die eingesetzten Schutz- und Erkennungsmechanismen wirken (Coverage, Zustand, Abdeckungsluecken).
▸ takes off the SOC: compliance evidence and coverage reports
DE.CM-09Supported2 · Alerted
Detect (Analysis)
DE-4Signatur- und IOC-basierte Angriffserkennung
Erkennung bekannter Angriffsmuster und Kompromittierungsindikatoren ueber stets aktuelle Signaturen und Reputations-/IOC-Abgleich.
▸ takes off the SOC: round-the-clock network monitoring
DE.AE-02Met2 · Alerted
DE-5Anomalie- und Verhaltenserkennung
Erkennung von Abweichungen vom Normalverhalten je Host und Prozess auf Basis von Baselines.
▸ takes off the SOC: reviewing and alerting on security events
DE.AE-02 / DE.AE-03Met2 · Alerted
DE-6Schadcode-Erkennung
Erkennung und Bewertung von Schadsoftware und verdaechtigen Dateien.
▸ takes off the SOC: endpoint monitoring and forensics
DE.CM-01Met3 · Auto-response
DE-7Quellenuebergreifende Korrelation
Verknuepfung von Ereignissen aus Netzwerk, Endpoint und Threat Intelligence, um zusammengehoerende Angriffe (z. B. C2) sichtbar zu machen.
▸ takes off the SOC: aggregating and correlating thousands of single alerts
DE.AE-03Met2 · Alerted
DE-8Threat Intelligence als Detektions-Input
Fortlaufende Aufnahme und Verarbeitung von Bedrohungsinformationen (IoCs, Angriffsmethoden), um Erkennungsregeln aktuell zu halten.
▸ takes off the SOC: aggregating and correlating thousands of single alerts
DE.AE-07 / ID.RA-07Met2 · Alerted
DE-9Wiederholte Pruefung mit neuen Erkenntnissen (Retro-Detektion)
Bereits gepruefte Daten werden regelmaessig automatisch erneut auf sicherheitsrelevante Ereignisse untersucht, sobald neue Erkenntnisse vorliegen.
▸ takes off the SOC: reviewing and alerting on security events
DE.AE-02Met2 · Alerted
DE-10Ereignisbewertung, Triage und Klassifizierung
Unterscheidung von Ereignis, Vorfall und Schwachstelle sowie Priorisierung nach Schwere und Kritikalitaet als Bindeglied von Detektion zu Reaktion.
▸ takes off the SOC: incident triage, prioritization and case creation
DE.AE-08 / RS.MA-03Met2 · Alerted
DE-11Alarmschwellen mit ausgeloester zeitnaher Reaktion
Definierte Schwellenwerte, deren Ueberschreitung automatisch qualifizierte Alarme und Reaktionsprozesse ausloest.
▸ takes off the SOC: reviewing and alerting on security events
DE.AE-06 / RS.MA-01Met3 · Auto-response
Respond
RS-1Strukturierte Vorfallbearbeitung
Geordnete Bearbeitung erkannter Vorfaelle ueber einen definierten Lebenszyklus mit revisionssicherer Fallakte.
RS.MA-01Met3 · Auto-response
RS-2Eindaemmung und Wiederherstellung
Zugeschnittene Massnahmen zur Eindaemmung und Schadensbegrenzung nach erkanntem Vorfall.
▸ takes off the SOC: containing and blocking attackers
RS.MI-01 / RS.MI-02Met3 · Auto-response
RS-3Automatisierte Erst-Reaktion (Active Response)
Automatische, je Netz kontrollierbare Sofortmassnahmen (Block, Quarantaene, Prozess-Stopp) zur unmittelbaren Eindaemmung, mit Human-in-the-loop wo geboten.
▸ takes off the SOC: round-the-clock network monitoring
RS.MI-01Met3 · Auto-response
RS-4Meldefaehigkeit mit kurzen Fristen
Bereitstellung der fuer die gesetzliche Meldung noetigen Informationen (Schwere, Auswirkung, IoCs) innerhalb kurzer Fristen. Die formale Meldung bleibt Pflicht des Betreibers.
▸ takes off the SOC: incident triage, prioritization and case creation
RS.CO-02 / RS.CO-03Supported2 · Alerted
RS-5Forensik und Beweissicherung
Integere Sammlung und Aufbewahrung von Beweismitteln (Artefakte, Chain of Custody), damit erkannte Angriffe spaeter pruef- und nachweisbar sind.
▸ takes off the SOC: forensic artifact collection and evidence preservation
RS.AN-03 / RS.AN-07Supported3 · Auto-response
Improve
IM-1Wirksamkeitsmessung, Tuning und Lessons Learned
Fortlaufende Messung und Verbesserung der Detektions- und Reaktionsfaehigkeit, Nachjustieren der Regeln und Reduktion von Falsch-Positiven.
▸ takes off the SOC: manual IOC research and rule maintenance
ID.IM-01 / ID.IM-03SOC/MDR1 · Detected

What ZephSense takes off the SOC team

Of 23 operational core requirements, 22 run automatically (96%). In the table above, each requirement is marked in green with the SOC task ZephSense takes over automatically.

How the autonomous SOC works →

Frameworks mapped

Every core requirement is mapped to the relevant European and international frameworks. The full references per standard are in the matrices per standard.

EU legal frameworks

CIR 2024/2690 23/23DORA 21/23NIS2 20/23CRA 5/23CER 3/23

ISO/IEC and IEC standards

ISO 27001 23/23IEC 62443-3-3 19/23ISO 27035-3 13/23ISO 27039 10/23ISO 27035-1 7/23ISO 27043 4/23ISO 27035-2 2/23ISO 27002 1/23

International reference framework

NIST CSF 2.0 23/23

National additional regimes

ES (ENS) 22/23DE (SzA) 20/23BE (CyFun) 20/23FR (LPM) 17/23IT (Perimetro) 14/23AT (NISG) 1/23CH (ISG) 1/23NL (Cbw) 1/23PT 1/23

National regimes and reporting deadlines

Beyond the EU baseline, stricter national obligations apply. Details in the Europe overview.

FrameworkSpecifics for attack detectionDeadlines
NIS2 (EU)Detection as part of incident handling, baseline24h / 72h / 1M
DORA (EU)Explicit detection obligation for the financial sector4h / 24h / 72h
DeutschlandNamed SzA obligation (Sec. 31 BSIG), separate detailed document24h / 72h
FrankreichQualified probes and PDIS SOC duty (LPM/SAIV)ANSSI
ItalienPerimetro with very short reporting deadlines1h / 6h
SpanienENS with concrete monitoring controls (op.mon)NIS2
BelgienCyberFundamentals (certifiable) with DETECT functionNIS2

Structure your requirements

We show which European and national requirements apply to you and how ZephSense supports them technically. The German BSI SzA has its own detailed document.