CCI-004651
CCI-004651 Definition
Establish and maintain a cyber threat hunting capability to search for indicators of compromise in organizational systems.
| Status | |
| Type | CheckType.technical |
Master Assessment Datasheet
Implementation Guidance
Determine if a cyber threat capability is established and maintained to search for indicators of compromise in organizational systems.
Validation Procedures
Examine: [SELECT FROM: Risk assessment policy; assessment reports; audit records/event logs; threat hunting capability; system security plan; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with threat hunting responsibilities; system/network administrators; organizational personnel with security responsibilities]. Test: [SELECT FROM: Organizational processes for assessments and audits; mechanisms/tools supporting and/or implementing threat hunting capabilities].