NIST CSF with ARRTECH

Records for the outcomes in your target profile.

Schedule a meeting

NIST CSF 2.0 · Mapped Sep 24, 2026

Records for the Detect and Respond outcomes

Log, detect, respond and preserve, and see plainly what stays with you.

Requirements

ClauseWhat it asksARRTECH
ID.AM-07Data inventoried.DLP discovery. →
PR.PS-04Log records generated.Classified events. →
DE.CM-01Networks monitored.Network and access logs. →
DE.AE-03Information correlated.Correlation across sources. →
RS.MA-02Incident reports triaged.Case records. →
RS.AN-06Actions recorded, integrity preserved.Signed, chained logs. →
RS.AN-07Data collected with integrity.Signed export with a verifier. →

Assets

Know where your data sits

ARRTECH DLP discovery scans endpoints, file servers and SQL databases, inventories what it finds by classification and labels files by rule.

Logging

Generate log records in one form

ARRTECH SIEM classification rules turn vendor codes into common event categories, graded Informational to Critical, so one search covers every vendor. MITRE ATT&CK tactic and technique are columns on each classified event.

Detection

See when a source goes quiet

The Data Sources page shows each source’s status, last read time and a silent-source alert, so a missing source is visible before your assessor finds it.

Response

Respond with a person deciding

A case carries its type, severity, assignee, SLA, MITRE tactic and kill-chain phase, sub-cases and history, and downloads as a case report. ARRTECH SOAR opens incidents from SIEM alerts and keeps an execution history of playbook runs. The Operator node emails a person with up to five options and waits.

Provenance

Preserve integrity and provenance

ARRTECH SIEM hashes and signs every write and chains each signature file to the one before, so a changed or missing file breaks the chain. Any source exports with a standalone verification tool, so your assessor checks it without your SIEM.

Limits

Know what stays with you

No ARRTECH product produces the record for these requirements.

GV

Governance. That is your organization’s own work.

RC.RP

Recovery plan execution. ARRTECH sells no backup product.

PR.AA-03

Authentication. ARRTECH does not claim MFA to its consoles. The record comes from your identity system.

ID.RA-01

Vulnerability identification. ARRTECH sells no vulnerability scanner.

By rule

Naming a clause is not a claim of certification.

ID.AM-07

Maintain inventories of data and metadata. ARRTECH: DLP discovery by classification.

PR.PS-04

Generate log records and make them available for monitoring. ARRTECH: classification rules across every vendor.

DE.CM-01

Monitor networks and network services for adverse events. ARRTECH: collection from more than 500 source types.

DE.AE-03

Correlate information from multiple sources. ARRTECH: correlation rules across sources.

RS.MA-02

Triage and validate incident reports. ARRTECH: case records with severity, assignee and SLA.

RS.AN-06

Record investigation actions and preserve the records’ integrity and provenance. ARRTECH: every write hashed, signed and chained.

RS.AN-07

Collect incident data and preserve its integrity and provenance. ARRTECH: signed exports with a standalone verification tool.

Questions

Is there a CSF certification?

No. NIST does not offer certifications or endorsements of CSF-related products.

Is there a ready CSF report?

No ready report is named. A saved query becomes a report, on a schedule.

Can our assessor check the logs without ARRTECH?

Yes. Any source exports with its signatures, the SIEM certificate and a standalone verification tool.

Which outcomes fit best?

RS.AN-06 and RS.AN-07, which ask for preserved integrity and provenance.

Sources

Guide

What is NIST CSF 2.0?

A voluntary framework of cybersecurity outcomes, published by NIST in February 2024.

What are the six functions?

Govern, Identify, Protect, Detect, Respond and Recover.

What is a profile?

A description of your current or target outcomes, used to plan the gap between them.

Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Available now

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Early access

Prove every log. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.

ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.