What is an incident?
To recap what we discussed back in Chapter 5, Introduction to Security Monitoring, an incident can be described as an occurrence of an event. Therefore, a security incident can be described as an occurrence of a security-related event – something that's happening to the security posture of the ICS environment that we are interested in and want to detect. To detect interesting security incidents, we need to be monitoring for them with security monitoring tools and practices.
The following are some examples of security incidents,:
- Executing malicious code on a system
- Impaired or disrupted availability of ICS systems or equipment (DCS, SIS, PLC, HMI, SCADA, and more)
- Malicious or damaging interaction with computing or production resources
- Unauthorized changes to a Programmable Logic Controller (PLC) or Human Machine Interface (HMI) program
- Unauthorized access to a building or restricted area of a building
- Unauthorized access...