Event that threatens the confidentiality, integrity, or availability of information or systems.
A security incident is any event that potentially compromises the confidentiality, integrity, or availability of information or systems—unauthorised access, malware infection, data breach, denial of service, or policy violation. Not all incidents are equal; severity assessment determines response level. Some incidents (like personal data breaches) have regulatory reporting requirements. Effective incident management requires clear definitions of what constitutes an incident and severity levels.
Why It Matters
The DSC Perspective:
Clear incident definitions ensure consistent response. Know what qualifies as an incident, how to report it, and what response is required. Without clear definitions, incidents may go unreported or inappropriately escalated.
