Records for the Detect and Respond outcomes
Log, detect, respond and preserve, and see plainly what stays with you.
Requirements
| Clause | What it asks | ARRTECH |
|---|---|---|
| ID.AM-07 | Data inventoried. | DLP discovery. → |
| PR.PS-04 | Log records generated. | Classified events. → |
| DE.CM-01 | Networks monitored. | Network and access logs. → |
| DE.AE-03 | Information correlated. | Correlation across sources. → |
| RS.MA-02 | Incident reports triaged. | Case records. → |
| RS.AN-06 | Actions recorded, integrity preserved. | Signed, chained logs. → |
| RS.AN-07 | Data collected with integrity. | Signed export with a verifier. → |
Assets
Know where your data sits
ARRTECH DLP discovery scans endpoints, file servers and SQL databases, inventories what it finds by classification and labels files by rule.
Logging
Generate log records in one form
ARRTECH SIEM classification rules turn vendor codes into common event categories, graded Informational to Critical, so one search covers every vendor. MITRE ATT&CK tactic and technique are columns on each classified event.
Detection
See when a source goes quiet
The Data Sources page shows each source’s status, last read time and a silent-source alert, so a missing source is visible before your assessor finds it.
Response
Respond with a person deciding
A case carries its type, severity, assignee, SLA, MITRE tactic and kill-chain phase, sub-cases and history, and downloads as a case report. ARRTECH SOAR opens incidents from SIEM alerts and keeps an execution history of playbook runs. The Operator node emails a person with up to five options and waits.
Provenance
Preserve integrity and provenance
ARRTECH SIEM hashes and signs every write and chains each signature file to the one before, so a changed or missing file breaks the chain. Any source exports with a standalone verification tool, so your assessor checks it without your SIEM.
Limits
Know what stays with you
No ARRTECH product produces the record for these requirements.
GV
Governance. That is your organization’s own work.
RC.RP
Recovery plan execution. ARRTECH sells no backup product.
PR.AA-03
Authentication. ARRTECH does not claim MFA to its consoles. The record comes from your identity system.
ID.RA-01
Vulnerability identification. ARRTECH sells no vulnerability scanner.
By rule
Naming a clause is not a claim of certification.
ID.AM-07
Maintain inventories of data and metadata. ARRTECH: DLP discovery by classification.
PR.PS-04
Generate log records and make them available for monitoring. ARRTECH: classification rules across every vendor.
DE.CM-01
Monitor networks and network services for adverse events. ARRTECH: collection from more than 500 source types.
DE.AE-03
Correlate information from multiple sources. ARRTECH: correlation rules across sources.
RS.MA-02
Triage and validate incident reports. ARRTECH: case records with severity, assignee and SLA.
RS.AN-06
Record investigation actions and preserve the records’ integrity and provenance. ARRTECH: every write hashed, signed and chained.
RS.AN-07
Collect incident data and preserve its integrity and provenance. ARRTECH: signed exports with a standalone verification tool.
Questions
Is there a CSF certification?
No. NIST does not offer certifications or endorsements of CSF-related products.
Is there a ready CSF report?
No ready report is named. A saved query becomes a report, on a schedule.
Can our assessor check the logs without ARRTECH?
Yes. Any source exports with its signatures, the SIEM certificate and a standalone verification tool.
Which outcomes fit best?
RS.AN-06 and RS.AN-07, which ask for preserved integrity and provenance.
Sources
Guide
What is NIST CSF 2.0?
A voluntary framework of cybersecurity outcomes, published by NIST in February 2024.
What are the six functions?
Govern, Identify, Protect, Detect, Respond and Recover.
What is a profile?
A description of your current or target outcomes, used to plan the gap between them.
Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Prove every log. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.