The result in numbers
Core requirements (NIST CSF 2.0)
Addressed by ZephSense/service
Auto-detected & alerted
Automated response (active response)
Frameworks mapped
Met technically by the platform
The maturity level reflects that ZephSense not only detects but responds automatically. The short reporting deadlines (NIS2 24h/72h, DORA 4h, Italy 1h/6h) are in practice only achievable with automation.
Coverage and automation maturity
Each core requirement has two assessments. Coverage shows how ZephSense supports it. The maturity level shows how far automation reaches.
Coverage: Met Met · SOC/MDR SOC/MDR · Supported Supported · Operator Operator
Maturity: 1 · Detected · 2 · Alerted · 3 · Auto-response
- 1 · Detected – the relevant data is captured and made visible automatically.
- 2 · Alerted – the platform detects on its own and alerts automatically.
- 3 · Auto-response – the platform responds automatically (containment), controllable per network, with human-in-the-loop where appropriate.
The Detection & Response core catalogue
23 functional core requirements along NIST CSF 2.0, each mapped to a ZephSense capability.
| ID | Core requirement | NIST CSF | Coverage | Maturity |
|---|---|---|---|---|
| Govern | ||||
| GV-1 | Dokumentierte Detection-&-Response-Leitlinie und Rollen Ein formal dokumentierter Prozess fuer Erkennung und Reaktion mit klaren Rollen, Verantwortlichkeiten, Eskalations- und Kommunikationswegen ueber den gesamten Vorfallslebenszyklus. ▸ takes off the SOC: initial response and incident containment | GV.RR-02 / GV.PO-01 | Supported | 1 · Detected |
| Protect (Logging) | ||||
| PR-1 | Systematische Erfassung sicherheitsrelevanter Ereignisse Risikobasiertes Erzeugen und Sammeln sicherheitsrelevanter Protokolldaten aus Netzwerk, Systemen, Endpoints, Authentifizierung und privilegierten Zugriffen. ▸ takes off the SOC: round-the-clock network monitoring | PR.PS-04 / DE.CM | Met | 1 · Detected |
| PR-2 | Zentrale Sammlung, Normalisierung und Aufbereitung Zusammenfuehren der Protokolldaten an zentraler Stelle mit Filterung, Normalisierung (einheitliches Zeitformat) und Aggregation, damit sie auswertbar werden. ▸ takes off the SOC: collecting and preparing the log data | DE.AE-03 | Met | 1 · Detected |
| PR-3 | Integritaets- und Zugriffsschutz der Protokolldaten Manipulationsgeschuetzte, integritaetsgesicherte Ablage der Protokolle mit rollenbasiertem Zugriffsschutz, damit sie als Nachweis belastbar bleiben. ▸ takes off the SOC: collecting and preparing the log data | PR.PS-04 / PR.AA | Met | 1 · Detected |
| PR-4 | Zeitsynchronisation der Datenquellen Einheitliche, synchronisierte Zeitbasis fuer die Korrelation ueber verschiedene Quellen. (Die Quell-Uhren stellt der Betreiber; die Plattform vereinheitlicht eingehende Zeitformate.) ▸ takes off the SOC: aggregating and correlating thousands of single alerts | PR.PS-04 | Supported | 1 · Detected |
| PR-5 | Aufbewahrung nach definierten Fristen Konfigurierbare Aufbewahrung und Loeschung der Protokolldaten entsprechend den rechtlichen und regulatorischen Fristen. ▸ takes off the SOC: collecting and preparing the log data | PR.PS-04 | Met | 1 · Detected |
| Detect (Monitoring) | ||||
| DE-1 | Kontinuierliche Netzwerkueberwachung Fortlaufende, moeglichst automatisierte Ueberwachung des Netzwerkverkehrs an internen und externen Uebergaengen (Flow-/Protokollanalyse, DNS). ▸ takes off the SOC: reviewing and alerting on security events | DE.CM-01 | Met | 2 · Alerted |
| DE-2 | Kontinuierliche Endpoint- und Systemueberwachung Fortlaufende Ueberwachung von Servern und Endpoints auf sicherheitsrelevante Aktivitaeten und Prozessverhalten. ▸ takes off the SOC: reviewing and alerting on security events | DE.CM-01 / DE.CM-03 | Met | 2 · Alerted |
| DE-3 | Ueberwachung der Wirksamkeit der Sicherheitsmechanismen Laufende Kontrolle, ob die eingesetzten Schutz- und Erkennungsmechanismen wirken (Coverage, Zustand, Abdeckungsluecken). ▸ takes off the SOC: compliance evidence and coverage reports | DE.CM-09 | Supported | 2 · Alerted |
| Detect (Analysis) | ||||
| DE-4 | Signatur- und IOC-basierte Angriffserkennung Erkennung bekannter Angriffsmuster und Kompromittierungsindikatoren ueber stets aktuelle Signaturen und Reputations-/IOC-Abgleich. ▸ takes off the SOC: round-the-clock network monitoring | DE.AE-02 | Met | 2 · Alerted |
| DE-5 | Anomalie- und Verhaltenserkennung Erkennung von Abweichungen vom Normalverhalten je Host und Prozess auf Basis von Baselines. ▸ takes off the SOC: reviewing and alerting on security events | DE.AE-02 / DE.AE-03 | Met | 2 · Alerted |
| DE-6 | Schadcode-Erkennung Erkennung und Bewertung von Schadsoftware und verdaechtigen Dateien. ▸ takes off the SOC: endpoint monitoring and forensics | DE.CM-01 | Met | 3 · Auto-response |
| DE-7 | Quellenuebergreifende Korrelation Verknuepfung von Ereignissen aus Netzwerk, Endpoint und Threat Intelligence, um zusammengehoerende Angriffe (z. B. C2) sichtbar zu machen. ▸ takes off the SOC: aggregating and correlating thousands of single alerts | DE.AE-03 | Met | 2 · Alerted |
| DE-8 | Threat Intelligence als Detektions-Input Fortlaufende Aufnahme und Verarbeitung von Bedrohungsinformationen (IoCs, Angriffsmethoden), um Erkennungsregeln aktuell zu halten. ▸ takes off the SOC: aggregating and correlating thousands of single alerts | DE.AE-07 / ID.RA-07 | Met | 2 · Alerted |
| DE-9 | Wiederholte Pruefung mit neuen Erkenntnissen (Retro-Detektion) Bereits gepruefte Daten werden regelmaessig automatisch erneut auf sicherheitsrelevante Ereignisse untersucht, sobald neue Erkenntnisse vorliegen. ▸ takes off the SOC: reviewing and alerting on security events | DE.AE-02 | Met | 2 · Alerted |
| DE-10 | Ereignisbewertung, Triage und Klassifizierung Unterscheidung von Ereignis, Vorfall und Schwachstelle sowie Priorisierung nach Schwere und Kritikalitaet als Bindeglied von Detektion zu Reaktion. ▸ takes off the SOC: incident triage, prioritization and case creation | DE.AE-08 / RS.MA-03 | Met | 2 · Alerted |
| DE-11 | Alarmschwellen mit ausgeloester zeitnaher Reaktion Definierte Schwellenwerte, deren Ueberschreitung automatisch qualifizierte Alarme und Reaktionsprozesse ausloest. ▸ takes off the SOC: reviewing and alerting on security events | DE.AE-06 / RS.MA-01 | Met | 3 · Auto-response |
| Respond | ||||
| RS-1 | Strukturierte Vorfallbearbeitung Geordnete Bearbeitung erkannter Vorfaelle ueber einen definierten Lebenszyklus mit revisionssicherer Fallakte. | RS.MA-01 | Met | 3 · Auto-response |
| RS-2 | Eindaemmung und Wiederherstellung Zugeschnittene Massnahmen zur Eindaemmung und Schadensbegrenzung nach erkanntem Vorfall. ▸ takes off the SOC: containing and blocking attackers | RS.MI-01 / RS.MI-02 | Met | 3 · Auto-response |
| RS-3 | Automatisierte Erst-Reaktion (Active Response) Automatische, je Netz kontrollierbare Sofortmassnahmen (Block, Quarantaene, Prozess-Stopp) zur unmittelbaren Eindaemmung, mit Human-in-the-loop wo geboten. ▸ takes off the SOC: round-the-clock network monitoring | RS.MI-01 | Met | 3 · Auto-response |
| RS-4 | Meldefaehigkeit mit kurzen Fristen Bereitstellung der fuer die gesetzliche Meldung noetigen Informationen (Schwere, Auswirkung, IoCs) innerhalb kurzer Fristen. Die formale Meldung bleibt Pflicht des Betreibers. ▸ takes off the SOC: incident triage, prioritization and case creation | RS.CO-02 / RS.CO-03 | Supported | 2 · Alerted |
| RS-5 | Forensik und Beweissicherung Integere Sammlung und Aufbewahrung von Beweismitteln (Artefakte, Chain of Custody), damit erkannte Angriffe spaeter pruef- und nachweisbar sind. ▸ takes off the SOC: forensic artifact collection and evidence preservation | RS.AN-03 / RS.AN-07 | Supported | 3 · Auto-response |
| Improve | ||||
| IM-1 | Wirksamkeitsmessung, Tuning und Lessons Learned Fortlaufende Messung und Verbesserung der Detektions- und Reaktionsfaehigkeit, Nachjustieren der Regeln und Reduktion von Falsch-Positiven. ▸ takes off the SOC: manual IOC research and rule maintenance | ID.IM-01 / ID.IM-03 | SOC/MDR | 1 · Detected |
What ZephSense takes off the SOC team
Of 23 operational core requirements, 22 run automatically (96%). In the table above, each requirement is marked in green with the SOC task ZephSense takes over automatically.
Frameworks mapped
Every core requirement is mapped to the relevant European and international frameworks. The full references per standard are in the matrices per standard.
EU legal frameworks
ISO/IEC and IEC standards
International reference framework
National additional regimes
National regimes and reporting deadlines
Beyond the EU baseline, stricter national obligations apply. Details in the Europe overview.
| Framework | Specifics for attack detection | Deadlines |
|---|---|---|
| NIS2 (EU) | Detection as part of incident handling, baseline | 24h / 72h / 1M |
| DORA (EU) | Explicit detection obligation for the financial sector | 4h / 24h / 72h |
| Deutschland | Named SzA obligation (Sec. 31 BSIG), separate detailed document | 24h / 72h |
| Frankreich | Qualified probes and PDIS SOC duty (LPM/SAIV) | ANSSI |
| Italien | Perimetro with very short reporting deadlines | 1h / 6h |
| Spanien | ENS with concrete monitoring controls (op.mon) | NIS2 |
| Belgien | CyberFundamentals (certifiable) with DETECT function | NIS2 |
Structure your requirements
We show which European and national requirements apply to you and how ZephSense supports them technically. The German BSI SzA has its own detailed document.