Annex I · Objective 04
Detect
Detecting attempts to recognize adverse events in good time through continuous monitoring and analysis.
Complete structure
Categories and controls.
Select each category to see all the codes and titles that make up it.
DE.MCContinuous Security Monitoring7 checks
- DE.MC-1
Networks and systems are monitored to detect potential incidents.
- DE.MC-2
The physical environment is monitored to detect potential safety incidents.
- DE.MC-3
Staff activity is monitored to detect potential incidents.
- DE.MC-4
The entity shall implement mechanisms for malicious code detection.
- DE.MC-5
Use of unauthorized applications on mobile devices is detected.
- DE.MC-6
The activities of external providers shall be monitored for incident detection.
- DE.MC-7
Hardware, software, production and data are monitored to detect adverse events.
DE.AEAnomalies and Events6 checks
- DE.AE-1
The events detected are analyzed.
- DE.AE-2
Events are collected and correlated from various sources and sensors.
- DE.AE-3
The estimated impact and scope of adverse events are understood and identified.
- DE.AE-4
Information on event detections is reported.
- DE.AE-5
Information on cyber-threats and context is integrated into event analysis.
- DE.AE-6
The criteria for reporting incidents are defined.
Application
How to work every control.
- Confirm full description in Annex I
- Set scope and responsibility
- Relating control with risk and critical services
- Associate implementation and evidence
- Record gaps, priority and deadline
- Review implementation and effectiveness
Primary source
Regulation No. 756/2026, of 22 June — Annex I
The codes and titles reproduce the structure of Annex I. Please refer to the official act for the full description and normative references of each control.