Ideally, incident detection precursors and indicators have different roles
and exhibit differing traits. Precursors serve to show that an incident will
likely occur in the future as the system is in use. On the other hand,
indicators signal that an incident is happening or has occurred. Precursors
draw their data from preestablished facts or information that is readily
available to security experts (Menges & Pernul, 2018). This information is
useful in assisting security professionals in developing plans to mitigate
and minimize possible risks. Indicators are symptoms that manifest to
indicate an existing problem and come in the form of security alerts,
reports, activity logs, or observations of unusual behavior (Maple, 2017).
Ideally, indicators vary in intensity and purpose depending on the intent of
system users and lead to deficiencies in the response process when an
incident occurs. However, precursors detect failures that may occur and
itemize possible issues that will arise. These differences are necessary to
categorize risk mitigation measures as precursors or indicators when
formulating plans for incident detection.
,The cybersecurity industry experiences significant challenges when
establishing incident detection parameters. Precursors are challenging