Home
Security Policies
Awareness Presentations
InfoSec Department
Report an Incident
Viruses/Hoaxes
Regulations
Security News
Security Library
Security Links
|
Incident Response
What is Considered an Incident?
An event is any observable occurrence in a computer system or network. Events include a user connecting to a share file, a server receiving a request for a Web page, a user sending e-mail, and a firewall blocking a connection attempt.
Adverse events are events with a negative consequence that is security-related in which there is a loss of:
data confidentiality
disruption of system integrity or corruption of data
a disruption of data availability, or denial of a computer service
An incident is any advese event like the following:
a system crash
a network packet flood
an unauthorized use of system privileges
a defacement of a Web page
the execution of malicious code that destroys data
An incident can be further expanded to include a violation or imminent threat of violation of:
security policies
acceptable use
standard security practices
Adverse events such as a natural disaster or a power failure would be excluded.
|