Security Event
Definition
Any observable occurrence in a system or network. Events are the raw material from which alerts and incidents are identified; the vast majority of events are routine and require no action.
- Scope
- Any observable occurrence in a system or network
- Relation to alerts
- Raw material from which alerts and incidents are derived
- Typical volume
- Large majority are routine and require no action
Common questions
How does a security event differ from a security incident?+
An event is simply something that happened and was logged; it only becomes an incident once analysis shows it violates policy or credibly threatens confidentiality, integrity or availability.
Why do SOC teams filter events before analysts see them?+
The sheer volume of routine events, such as normal logins or successful patch installs, would overwhelm analysts if every one required manual review, so correlation rules and thresholds narrow the flow down to what merits a look.
Related terms
- Alert
- A notification generated when an event or pattern of events matches a detection rule. Alerts require triage to determine whether they represent...
- Data Breach
- An incident in which an unauthorised party gains access to, copies, or discloses protected data. Breaches trigger specific legal notification requirements under...
- Insider Threat
- An incident originating from a person with legitimate access to an organisation's systems, whether through malicious intent (data theft, sabotage) or negligence...
- Ransomware
- Malware that encrypts or exfiltrates data and demands payment for restoration or suppression. Modern ransomware incidents often combine an availability impact (encrypted...
- Security Incident
- An event or chain of events that violates an organisation's security policy or credibly threatens the confidentiality, integrity, or availability of information...