1 / 2100%
Incident Detection Precursors and Indicators
Identifying incident detection precursors and indicators is essential in keeping
information systems safe and secure. According to Rapid7, the main difference between
incident detection precursors and incident detection indicators is that precursors suggest the
likelihood of an incident occurring while indicators give information on an incident that is
either occurring or has already occurred. Based on NIST SP 800-61, examples of precursors
include a hacker group announcing that it would attack the organization and web server logs
showing the utilization of the vulnerability scanner (Cichonski et a. 26). Although most
attacks do not have detectable precursors, identifying them allows an
organization to adopt measures to enhance its security posture to prevent
the incident. On the other hand, indicators are common. Examples
encompass files with unusual characters, antivirus alerts about an
infected host, and intrusion detection alerts ( . Once the Cichonski et al. 26)
organization has detected precursors and indicators, it should evaluate
them to determine the likelihood of them becoming attacks and the
Students also viewed