procedures for reporting the different types of events and weaknesses that might have an impact on the security of organisational assets. A formal process requires the timely reporting of any security events and weaknesses to a designated point of contact. Thus, we recommend that incident management participants consider adopting the ITU-T E.409 terminology (ITU 2004). Whereas the requirements differ across nations, ITU-T E.409 sees incident handling as typically aiming to support these requirements: Figure 22 – Protection principles 11.3.1.1 Prevent The preventive protection mechanisms come first. When adequate preventive protection mechanisms are in place, implemented via physical or logical protection, it is possible to identify and activate the detecting protection mechanisms. Physical controls could include barriers such as fences, lighting and gates. As discussed under cybersecurity technologies, logical preventive tools include tools that correlate logs from Security Enforcing Functions. The tools correlate logs in real time, establish whether an attack has occurred and either respond or alert an incident response module or team. 11.3.1.2 Detect The detection protection mechanisms could, in the simplest form be the checking of log files, logical or physical alarms, i.e., burglar alarms, fire alarms or other surveillance functions. One form of detection mechanism is the Intrusion Detection System (IDS). The section on cybersecurity tools discusses IDS including network and host-based types. 11.3.1.3 React Once an incident is detected and validated, action should follow. Actions include: (a) stopping an ongoing incident; (b) identifying scope/scale of incident; (c) limiting damage; (d) taking measures in order to investigate the course of events and (e) preventing the incident from recurring. 11.3.1.4 Deter Deterrence involves active steps to beat off attacks. As discussed under cybersecurity technologies, Intrusion Prevention Systems (IPSs) can react, in real-time, to block or prevent intrusions. IPSs drop offending packets on detecting malicious activity but allow all other traffic to pass through. Modern IPSs combine firewall, intrusion detection, antivirus and vulnerability assessment capabilities. 65

Select target paragraph3