10.
Information Security Incidents
10.1.
Detecting Information Security Incidents
Objective:
Recommended Control 1:
Recommended Control 2:
To ensure that appropriate tools, processes and procedures are
implemented to detect information security incidents, to
minimize impact and as part of the suite of good IT governance
activities
Agencies should develop, implement and maintain tools and
procedures covering the detection of potential information
security incidents, incorporating:
counter‐measures against malicious code
intrusion detection strategies
data egress monitoring & control
audit analysis
system integrity checking
vulnerability assessments
Agencies should use the results of the security risk assessment to
determine the appropriate balance of resources allocated to
prevention versus detection of information security incidents
Processes for the detection of information security incidents will assist in mitigating the most
common vectors used to exploit systems.
Many potential information security incidents are noticed by personnel rather than automated or
other software tools. Personnel should be well trained and aware of information security issues and
indicators of possible information security incidents.
Agencies may consider some of the tools described in the table below for detecting potential
information security incidents.
Tool
Description
Network and host Intrusion Detection Systems Monitor and analyze network and host activity,
(IDSs)
usually relying on a list of known attack signatures
to recognize/ detect malicious activity and potential
information security incidents
Anomaly detection systems
Monitor network and host activities that do not
conform to normal system activity
Intrusion Prevention Systems (IPS) and Host Based Some IDs are combined with functionality to
Intrusion Prevention Systems (HIPS)
counter detected attacks or anomalous activity
(IDS/IPS)
42