Podcast
Questions and Answers
What are five indicators of an incident?
What are five indicators of an incident?
- Intent of harm - malicious 2. Violates a security control 3. Indicates privileges greater than authorized 4. Exposure of an information asset or privileged function to unauthorized parties 5. Press attention
What distinguishes an event from an incident?
What distinguishes an event from an incident?
An event is a system occurrence that occurs regularly or system failure due to hardware or software malfunction. An incident involves intent to cause harm, violates security controls, indicates unauthorized privileges, exposes information, or receives press attention.
Why is it important to differentiate between incidents and events in the context of security?
Why is it important to differentiate between incidents and events in the context of security?
It is important to differentiate between incidents and events in the context of security because incidents require immediate attention and response, while events may not. Focusing on events can distract from identifying and addressing incidents that pose a greater threat.