Skip to main content

Pro audit program · v1.0

EDR Coverage Check

Are all endpoints actually covered by EDR, and is response automated? Quick coverage + tuning check.

  • General target area
  • NIST CSF framework
  • 6 controls in this program
  • Cyentrix Cyentrix Trusted Author

About this program

Are all endpoints actually covered by EDR, and is response automated? Quick coverage + tuning check.

Risks addressed

  • Critical Endpoint compromise goes undetected u2014 long dwell time
  • High Server estate excluded from EDR rollout
  • High EDR agent disabled by attacker / user
  • High Alerts ignored outside business hours

Controls (6)

  1. EDR deployed on 100% of corporate endpoints

    Critical

    Endpoint Detection and Response (EDR) solutions are deployed on all corporate-managed endpoints including workstations, laptops, and servers to provide continuous monitoring, threat detection, and incident response capabilities. These agents collect telemetry on process execution, network connections, file system changes, and…

    How to test + evidence

    Testing procedure: Compare EDR roster to HR + asset inventory; deviation <=2%.

    Evidence to collect: EDR roster vs inventory diff.

  2. EDR deployed on all servers

    High

    Endpoint Detection and Response (EDR) software is deployed and actively running on all production, development, staging, and test servers across the organization. EDR agents continuously monitor system activity, process execution, network connections, file changes, and registry modifications to detect suspicious…

    How to test + evidence

    Testing procedure: Same coverage check for production + non-production servers.

    Evidence to collect: EDR roster vs CMDB diff.

  3. Tamper protection enabled

    High

    Tamper protection is a security feature that prevents unauthorized users, malware, or malicious processes from disabling or altering critical security software components such as antivirus engines, real-time scanning, behavior monitoring, and cloud-delivered protection services. This control enforces system-level or kernel-level…

    How to test + evidence

    Testing procedure: EDR cannot be uninstalled / disabled without console action.

    Evidence to collect: EDR policy export.

  4. Auto-isolation playbook in place

    Medium

    An auto-isolation playbook defines the automated or semi-automated procedures for disconnecting compromised systems, user accounts, or network segments from production environments upon detection of specific threat indicators. This playbook integrates with SOAR platforms, EDR tools, or SIEM systems to trigger…

    How to test + evidence

    Testing procedure: Confirmed-malicious detections trigger host isolation automatically (or via 24x7 SOC).

    Evidence to collect: Playbook export + last invocation evidence.

  5. Alerts triaged 24x7

    High

    Alerts triaged 24x7 requires an organization to staff a security operations capability continuously, ensuring that security monitoring tools generate alerts that are acknowledged, categorized, and prioritized at all hours, including weekends and holidays. This control establishes a follow-the-sun or shift-based…

    How to test + evidence

    Testing procedure: Confirm SOC (in-house or MSSP) covers EDR alerts around the clock.

    Evidence to collect: SOC contract / staffing roster.

  6. Detection rules tuned monthly

    Low

    Detection rules tuned monthly refers to the systematic review, optimization, and adjustment of security event detection signatures, correlation rules, behavioral analytics thresholds, and threat hunting queries deployed in SIEM, EDR, NDR, and other security monitoring platforms. This process involves analyzing…

    How to test + evidence

    Testing procedure: Rule-tuning meeting cadence; false-positive rate trending down.

    Evidence to collect: Tuning meeting minutes.