9 Incident Detection and Response

DOI: 10.1201/b11355-9

An emergency is not the time to plan; it’s the time to react, so be informed.

Tom Ridge

What Is an Incident?

In regard to computers, an incident is the occurrence of any unwanted or unauthorized network event. These events could be the result of malicious intent or accident, but the end result always causes damage or disruption to network operations.

Incident Detection

Although firewalls are an excellent and necessary means of preventing malicious digital data packets from entering a network, firewalls are not foolproof and all firewalls will eventually allow in some “bad” traffic. Because firewalls are only gatekeepers located at the perimeter of a network, they have no capability ...

Get Asset Protection through Security Awareness now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.