Security event
Definition
Any observable occurrence in a system or network. Events are the raw material from which alerts and incidents are identified; the vast majority of events are routine and require no action.
Related terms
- Alert
- A notification generated when an event or pattern of events matches a detection rule. Alerts require triage to determine whether they represent...
- Data breach
- An incident in which an unauthorised party gains access to, copies, or discloses protected data. Breaches trigger specific legal notification requirements under...
- Insider threat
- An incident originating from a person with legitimate access to an organisation's systems, whether through malicious intent (data theft, sabotage) or negligence...
- Ransomware
- Malware that encrypts or exfiltrates data and demands payment for restoration or suppression. Modern ransomware incidents often combine an availability impact (encrypted...
- Security incident
- An event or chain of events that violates an organisation's security policy or credibly threatens the confidentiality, integrity, or availability of information...
Explained in
- What Is a Security IncidentAny observable occurrence in a system or network. Events are the raw material from which alerts and incidents are identified; the vast majority of events are r...