Cyber ​​incident management of personal data breaches

2. Cyber incident

Defining a Cyber Incident

An event is any observable occurrence within a system or network. Events include a user connecting to shared files, a server receiving a website request, a user sending an email, a firewall blocking a connection attempt, and similar activities.

Undesirable events are those with negative consequences, such as system crashes, packet flooding, unauthorised use of system privileges, unauthorised access to sensitive data, execution of malware that destroys data, and similar incidents.

An occurrence that actually or potentially threatens the confidentiality, integrity, or availability of an information system or the information it processes, stores, or transmits represents a violation or an imminent threat of violating security policies, security procedures, or acceptable‑use policies. Source: National Institute of Standards and Technology – Computer Security Incident / Security Incident from FIPS 200 and NIST SP 800‑12, SP 800‑128, SP 800‑137

According to NIST, the definition of a cyber incident refers to the compromise of one of the three key goals of information security, known as the CIA triad. The same definition is provided by the Croatian Cybersecurity Act:

An incident is an event that compromises the availability, authenticity, integrity, or confidentiality of stored, transmitted, or processed data, or of the services that network and information systems provide or enable access to.

The life cycle of a cyber incident

Figure 7: The life cycle of a cyber incident

Accessibility

Background Colour Background Colour

Font Face Font Face

Font Size Font Size

1

Text Colour Text Colour

Font Kerning Font Kerning

Image Visibility Image Visibility

Letter Spacing Letter Spacing

0

Line Height Line Height

1.2

Link Highlight Link Highlight