procedures for reporting the different types of events and weaknesses that might have
an impact on the security of organisational assets. A formal process requires the timely
reporting of any security events and weaknesses to a designated point of contact. Thus,
we recommend that incident management participants consider adopting the ITU-T
E.409 terminology (ITU 2004). Whereas the requirements differ across nations, ITU-T
E.409 sees incident handling as typically aiming to support these requirements:
Figure 22 – Protection principles
11.3.1.1 Prevent
The preventive protection mechanisms come first. When adequate preventive protection
mechanisms are in place, implemented via physical or logical protection, it is possible to
identify and activate the detecting protection mechanisms. Physical controls could
include barriers such as fences, lighting and gates. As discussed under cybersecurity
technologies, logical preventive tools include tools that correlate logs from Security
Enforcing Functions. The tools correlate logs in real time, establish whether an attack
has occurred and either respond or alert an incident response module or team.
11.3.1.2 Detect
The detection protection mechanisms could, in the simplest form be the checking of log
files, logical or physical alarms, i.e., burglar alarms, fire alarms or other surveillance
functions. One form of detection mechanism is the Intrusion Detection System (IDS). The
section on cybersecurity tools discusses IDS including network and host-based types.
11.3.1.3 React
Once an incident is detected and validated, action should follow. Actions include: (a)
stopping an ongoing incident; (b) identifying scope/scale of incident; (c) limiting damage;
(d) taking measures in order to investigate the course of events and (e) preventing the
incident from recurring.
11.3.1.4 Deter
Deterrence involves active steps to beat off attacks. As discussed under cybersecurity
technologies, Intrusion Prevention Systems (IPSs) can react, in real-time, to block or
prevent intrusions. IPSs drop offending packets on detecting malicious activity but allow
all other traffic to pass through. Modern IPSs combine firewall, intrusion detection, antivirus and vulnerability assessment capabilities.
65