An incident precursor is a noticeable indication or sign that an attack may
take place in the future based on a previous event. On the other hand,
incident detection indicators are noticeable indications that an attack is
currently happening or has happened in the past.
I currently work for a small business that fulfils contracts with the federal
government. The main incident detection precursor we are currently
noticing is the large amounts of media coverage on being secure from
cyber-attacks due to everything that has been going on with Russia, and
Ukraine. U.S federal government as well as banks and large companies
are scrambling trying to make sure they are safe from cyber-attacks. My
job has been making sure we are as secure as possible and following DoD
guidelines (especially pertaining to cyber security) which can lead to a lot
of challenges especially when most everyone is working from home.
Another challenge that arises is that precursors do not necessarily mean
that something is going to happen. Especially with such a broad precursor
such as telling U.S governments and corporations to prepare themselves
for attacks. Some people won’t take it seriously because they might not
think it will happen to them or it's just a small chance of them being the
next cyber-attack victim. An incident detection indicator that has
happened to my job is my boss getting a call from a friend saying that
someone called impersonating my boss, in order to get valuable
information. This leads us to think that some type of attack has already
happened or that is currently taking place. This was very challenging
because there was no warning beforehand. Indications only let you know if
something has or is currently happening to leave us to find and solve the
issue at hand.
Paul Cichonski, Tom Millar, Tim Grance, Karen Scarfone. 2012. Computer
Security Incident Handling Guide. p. 25-
34.http://seguridad.unicauca.edu.co/nist.sp.800-61r2.pdf.