10. Information Security Incidents 10.1. Detecting Information Security Incidents Objective: Recommended Control 1: Recommended Control 2: To ensure that appropriate tools, processes and procedures are implemented to detect information security incidents, to minimize impact and as part of the suite of good IT governance activities Agencies should develop, implement and maintain tools and procedures covering the detection of potential information security incidents, incorporating: counter‐measures against malicious code intrusion detection strategies data egress monitoring & control audit analysis system integrity checking vulnerability assessments Agencies should use the results of the security risk assessment to determine the appropriate balance of resources allocated to prevention versus detection of information security incidents Processes for the detection of information security incidents will assist in mitigating the most common vectors used to exploit systems. Many potential information security incidents are noticed by personnel rather than automated or other software tools. Personnel should be well trained and aware of information security issues and indicators of possible information security incidents. Agencies may consider some of the tools described in the table below for detecting potential information security incidents. Tool Description Network and host Intrusion Detection Systems Monitor and analyze network and host activity, (IDSs) usually relying on a list of known attack signatures to recognize/ detect malicious activity and potential information security incidents Anomaly detection systems Monitor network and host activities that do not conform to normal system activity Intrusion Prevention Systems (IPS) and Host Based Some IDs are combined with functionality to Intrusion Prevention Systems (HIPS) counter detected attacks or anomalous activity (IDS/IPS) 42

Select target paragraph3