What is a security incident?

A security incident is an event that violates an organization’s security policies and procedures and compromises the integrity, confidentiality, and availability of information assets. For example, a simple login to an SSH server is considered an event but a brute force attack using multiple logins to an SSH server is considered a security incident. All types of security incidents should be actionable either in an automated way or by a security analyst.

Get Practical Network Scanning now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.