-
Book Overview & Buying
-
Table Of Contents
-
Feedback & Rating
CompTIA CySA+ Study Guide: Exam CS0-002
By :
Security events are occurrences that may escalate into a security incident. An event is any observable occurrence in a system or network. A security event includes any observable occurrence that relates to a security function. A security incident is a violation or imminent threat of violation of computer security policies, acceptable use policies, or standard security practices. Every incident consists of one or more event, but every event is not an incident.
The cybersecurity incident response process has four phases. The four phases of incident response are preparation; detection and analysis; containment, eradication, and recovery; and post-incident activities. The process is not a simple progression of steps from start to finish. Instead, it includes loops that allow responders to return to prior phases as needed during the response.
Security event indicators include alerts, logs, publicly available information and people. Alerts originate from intrusion detection...
Change the font size
Change margin width
Change background colour