Information security incidents and breaches
If a company’s security policy is violated, it results in a security incident. It can be an event that compromises any one pillar of the Confidentiality, Integrity, and Availability (CIA) triad. A security breach is when an unauthorized entity gains access to the organization’s data, network, applications, or devices, which results in the disclosure of critical/sensitive information. An incident may or may not evolve as a breach.
Let us investigate a few examples to understand the difference between a security event, incident, and breach better:
- Let’s imagine that in the building of organization XYZ, a window that provides access to physical files with personally identifiable information is accidentally left open. This is an event. Now, if a couple of files are missing, resulting from this careless act, it results in an incident. If someone with malicious intentions gains access to the files and, as a result...