Security incidents
We start our conversation about security monitoring with a discussion around security incidents. This is because the ultimate goal of security monitoring is to detect, record, and alert on security incidents. We want to detect and address security-related incidents before they become a major issue.
An incident can be described as an occurrence of an event with a potentially undesirable or harmful outcome. With that, a security incident can therefore be described as an occurrence of a security-related event—something happening to the security posture of the ICS environment that we are interested in and want to detect. It is important to understand that not every event is a security incident—for example, somebody fat-fingering a password and generating a failed login event is not necessarily a security incident. What makes a security-related event a security incident is context. If the failed login event from before came from an account that has no...