Incident response – Detection: Detection refers to the process of identifying that an incident has occurred. This can be done through various methods, such as monitoring systems, using security software, or receiving alerts from employees or external sources. For example, a company may use a security information and event management (SIEM) system to monitor network activity and identify potential threats or set up alerts to notify IT staff of unusual activity.
Categories: CC D5: Security Operations | CCSP D5: Cloud Security Operations | CISM D4: Incident Management | CISSP D7: Security Operations | Security+ D4: Security Operations | SSCP D4: Incident Response and Recovery
« Back to Glossary Index