1 / 1100%
I chose the finance industry for this discussion. Like just about any other
industry, paying attention to both incident detection precursors and
indicators is important and will cost money if not dealt with properly.
Every enterprise should have time and money invested in a Security
Information and Event Management (SIEM) system to help with both types
of incident detection. Which is more serious and important to deal with
quickly between the two? I'll let you decide based on the details provided
here about these two topics. I could argue either way that a precursor is
more important than an indicator or vice-versa but I digress.
As defined by the NIST SP 800-61 on page 26 (1). A precursor is a sign
that an incident may occur in the future. Conversely, an indicator is a sign
that an incident may have occurred or may be occurring now. You would
think that if you handle every incident detection precursor properly, it
would prevent the attack so that no incident detection indicator would
Students also viewed