DTEX CNSSD 504 Requirements Mapping

  • INSIDER RISK MANAGEMENT
  • USER ACTIVITY MONITORING

Overview

DTEX maps CNSSD 504 UAM, data protection, chain of custody, retention, and Table 1 indicator requirements to capabilities marked met or exceeded. It encrypts user activity data at rest, in transit, and during use, monitors administrative access, and protects chain of custody with PKI (CAC) enabled access control, restricted roles, and data encryption. 

DTEX captures keystrokes, full application content, screen captures, file shadowing, and user-attributable UAM data. Alert and trigger data can be exported to third-party systems for storage, analysis, and investigation. DTEX also has a built-in data lake, and storage can be configured to meet or exceed the 5-year minimum retention requirement. 

DTEX’s privacy-by-design approach is specific: it collects 5MB of metadata per user per day to build a forensic audit trail and applies patented Pseudonymization™ to tokenize PII across username, email, domain name, and device name. DTEX also brings UAM data into UEBA analysis. The add-on DTEX Agentic Defenders continuously investigate, hunt, and summarize risk through Triage Guardian Agent, Threat Hunter Agent, and AI Risk Assistant. 

What You'll Learn

  • Which CNSSD 504 must requirements DTEX maps to met or exceeded capabilities, including data safeguards, chain of custody, keystroke monitoring, application content, screen capture, file shadowing, and user attribution.
  • How DTEX handles trigger data export, built-in data lake storage, and configurable retention for the 5-year minimum requirement.
  • Which CNSSD 504 Table 1 indicators DTEX supports, including account changes, authentication anomalies, baseline anomalies, exfiltration, network traffic anomalies, privilege violations, and user behavior anomalies.

Frequently Asked Questions

Which CNSSD 504 requirements does DTEX map to met or exceeded capabilities?

DTEX maps required UAM, data protection, chain of custody, retention, and Table 1 indicator coverage to capabilities marked met or exceeded. That includes data safeguards, keystroke monitoring, full application content, screen capture, file shadowing, and user-attributable UAM data. 

How does DTEX protect chain of custody and UAM data?

DTEX protects chain of custody with PKI (CAC) enabled access control, restricted roles, and data encryption. It encrypts user activity data at rest, in transit, and during use, and monitors administrative access. 

How does DTEX handle retention, export, and storage?

DTEX storage is configurable to meet or exceed the 5-year minimum retention requirement. Alert and trigger data is exportable to third-party systems for storage, analysis, and investigation, and DTEX has a built-in data lake. 

Which Table 1 insider risk indicators does DTEX support?

DTEX maps Table 1 indicators including account changes, authentication anomalies, baseline anomalies, exfiltration, network traffic anomalies, privilege violations, and user behavior anomalies. It also incorporates UAM data into UEBA analysis. 

How does DTEX use privacy by design?

DTEX collects 5MB of metadata per user per day to build a forensic audit trail and applies patented Pseudonymization™ to tokenize PII. Tokenized fields include username, email, domain name, and device name. 

How do Agentic Defenders support insider threat mitigation?

DTEX Agentic Defenders continuously investigate, hunt, and summarize risk. The add-on includes Triage Guardian Agent, Threat Hunter Agent, and AI Risk Assistant. 

Ready to Learn More?