Skip to main content
Role AvailabilityRead-OnlyInvestigatorAnalystManager
Security Continuous Monitoring (DE.CM): The information system and assets are monitored at discrete intervals to identify cybersecurity events and verify the effectiveness of protective measures. Unauthorized access to accounts will partially satisfy this control. Associated Frameworks: NIST SP 800-53 Rev. 4 AU-12, CA-7, CM-3, CM-8, PE-3, PE-6, PE-20, SI-4 Filters used by NIST CSF Windows Control DE.CM-7: Monitoring for Unauthorized Personnel, Connections, Devices, and Software is Performed
FieldValues
Data Source”Windows NxLog”, “AlienVault Agent - Windows EventLog”, “AWS Directory Service”, “ManageEngine ADAudit Plus”, “Azure Windows Events”, “AWSWindows XML”, “AWSWindows”, “Windows PowerShell NxLog”, “Windows SQL NxLog”
Reporting Device Rule ID”529”, “530”, “531”, “532”, “533”, “534”, “535”, “536”, “537”, “539”, “552”, “644”, “675”, “4625”, “4648”, “4771”, “4740”
Category”Security”, “Logon”
To generate the NIST CSF Windows Control DE.CM-7 report
  1. Go to Reports > Compliance Templates.
  2. On the left navigation pane, click NIST CSF.
  3. Click Generate Report on the specific line for this report. The Configure Report dialog box appears.
  4. Click Edit Filters if you want to modify the selected filters, and then click Continue to Filters.
  5. Make the required modifications, and then click Edit Report.
  6. Click the date field if you want to choose a different date range. Choose Last Hour, Last 24 Hours, Last 7 Days, Last 30 Days, Last 90 Days, or Custom Range to set a particular date range.
  7. Select the Format of the report. It can either be CSV or PDF.
  8. Select a Schedule for the report if you want to generate it again: Never, Daily, Weekly, Bi-weekly, and Monthly.
  9. Enter an email address in which to send the report. You may also select the Send to my Email Address option to add your email automatically.
  10. Select the Enable link expiration option.
    This link is delivered by email and expires in 14 days.
  11. Click Next.
  12. In the Report Name field, enter a name for the report. This name will be displayed on the Saved Reports page.
  13. (OPTIONAL) Enter a Report Description.
  14. Under the Number of Records section, select the maximum number of records to include in the report: 20, 50, 100, 500, 1000, or 2500.
  15. If you have previously chosen the PDF format, you will see the Graphs section, which you can use to include additional views. You can add to or remove graphs from the report by clicking the and icons.
  16. Click Run to run the report.
    You can also click Save & Run if you wish to keep the report in your Saved Reports on USM Anywhere page and receive the report in the indicated email.