Cybersecurity GRC 15 items
Endpoint Detection & Response (EDR) Program Review
Reviews endpoint protection coverage, detection efficacy, and response capabilities of the EDR/XDR deployment across managed devices.
CIS v8NIST 800-53MITRE ATT&CK
Free PDF · enter your email to download.
Coverage & Deployment
- Is an EDR agent deployed on all servers, workstations, and laptops? *
- What percentage of the endpoint inventory has a healthy, reporting EDR agent?
- Are alerts generated for endpoints missing or with disabled EDR agents? *
- Is anti-malware signature and engine content updated automatically? *
Detection Capability
- Does the EDR provide behavioral and heuristic detection beyond signatures? *
- Are detections mapped to MITRE ATT&CK techniques?
- Is detection efficacy validated with atomic tests or purple-team exercises? *
- Are exclusions reviewed and approved to prevent detection blind spots? *
Response & Containment
- Can analysts remotely isolate a compromised endpoint from the console? *
- Are automated response playbooks configured for high-fidelity detections?
- Is endpoint telemetry retained long enough to support investigations? *
- Is the EDR integrated with the SIEM or SOAR for correlation? *
Monitoring & Threat Hunting
- Is the EDR console monitored 24x7 by internal staff or an MDR provider? *
- Are proactive threat hunts conducted using EDR telemetry?
- Are mean time to detect and respond metrics tracked and reviewed? *
Download the full Endpoint Detection & Response (EDR) Program Review checklist
Get it as a clean, printable PDF — free.
