MLchartDataset catalogue

Cyber incident

Term · Cybersecurity · MLC-T-CYB-001155

1. Any observable occurrence involving computing assets, including physical and virtual platforms, networks, services, and cloud environments.

2. An occurrence that actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or an information system or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.

3. An occurrence (e.g., an auditable event or flag) considered to have potential security implications to the system or its environment that may require further action (noting, investigating, or reacting).

4. Any event that attempts to change the security state of the system, (e.g., change discretionary access controls, change the security level of the subject, change user password, etc.). Also, any event that attempts to violate the security policy of the system, (e.g., too many attempts to login, attempts to violate the mandatory access control limits of a device, attempts to downgrade a file, etc.).

5. An occurrence that actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.

6. Any observable occurrence in a network or system.

7. Actions taken through the use of an information system or network that result in an actual or potentially adverse effect on an information system, network, and/or the information residing therein. See incident. See also event, security-relevant event, and intrusion.

8. Any observable occurrence in a network or information system.

9. Actions taken through the use of an information system or network that result in an actual or potentially adverse effect on an information system, network, and/or the information residing therein.

10. An occurrence that actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or an information system; or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.

11. An occurrence that actually or potentially jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or an information system; or constitutes a violation or imminent threat of violation of security policies, security procedures, or acceptable use policies.

12. Any observable occurrence in a system.

13. An occurrence that actually or potentially jeopardizes the confidentiality, integrity, or availability of a system or the information the system processes, stores, or transmits or that constitutes a violation or imminent threat of violation of security policies, security procedures, or acceptable use policies.

14. Occurrence or change of a particular set of circumstances.

15. Anomalous or unexpected event, set of events, condition, or situation at any time during the life cycle of a project, product, service, or system.

Table 1. Record
IdentifierMLC-T-CYB-001155
FieldCybersecurity
Abbreviationevent
Synonymsincident; security-relevant event
ReferencesNIST SP 800-61r3; NIST SP 800-172r3 from GAO-19-128; CNSSI 4009-2022; CNSSI 4009-2022 from DoD 5200.28-STD; CNSSI 4009-2015 from FIPS 200 (Adapted); CNSSI 4009-2022 from 44 U.S.C., Sec. 3552; CNSSI 4009-2015 from NIST SP 800-61 Rev. 2; CNSSI 4009-2015; NIST SP 800-37 Rev. 2 from NIST SP 800-61 Rev. 2 (adapted); NIST SP 800-160 Vol. 2 [Superseded] from CNSSI 4009-2015, CNSSI 4009-2022; NIST SP 800-160 Vol. 2 Rev. 1 from CNSSI 4009-2015, CNSSI 4009-2022; NIST SP 800-171 Rev. 2 [Superseded] from 44 U.S.C., Sec. 3552; NIST SP 800-37 Rev. 2 from 44 U.S.C., Sec. 3552; NIST SP 800-53 Rev. 5 from PL 113-283 (FISMA); NIST SP 800-172 [Superseded] from 44 U.S.C., Sec. 3552; NIST SP 800-172A [Superseded] from 44 U.S.C., Sec. 3552; NIST SP 800-171r3 from 44 U.S.C., Sec. 3552; NIST SP 800-128 from 44 U.S.C., Sec. 3552; NIST SP 800-53 Rev. 5 from NIST SP 800-61 Rev. 2 (Adapted); NIST SP 800-171 Rev. 1 [Superseded] from FIPS 200 (Adapted); NIST SP 800-160 Vol. 1 from ISO Guide 73; NIST SP 800-160v1r1 from ISO Guide 73; NIST SP 800-160 Vol. 1 from ISO/IEC/IEEE 15288; NIST SP 800-160v1r1 from ISO/IEC/IEEE 15288:2015; NIST CSRC Glossary
See alsoEvent; Incident; Intrusion; Security-relevant event
Record as JSON
{
  "id": "MLC-T-CYB-001155",
  "term": "Cyber incident",
  "field": "Cybersecurity",
  "definition": "1. Any observable occurrence involving computing assets, including physical and virtual platforms, networks, services, and cloud environments.\n\n2. An occurrence that actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or an information system or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.\n\n3. An occurrence (e.g., an auditable event or flag) considered to have potential security implications to the system or its environment that may require further action (noting, investigating, or reacting).\n\n4. Any event that attempts to change the security state of the system, (e.g., change discretionary access controls, change the security level of the subject, change user password, etc.). Also, any event that attempts to violate the security policy of the system, (e.g., too many attempts to login, attempts to violate the mandatory access control limits of a device, attempts to downgrade a file, etc.).\n\n5. An occurrence that actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.\n\n6. Any observable occurrence in a network or system.\n\n7. Actions taken through the use of an information system or network that result in an actual or potentially adverse effect on an information system, network, and/or the information residing therein. See incident. See also event, security-relevant event, and intrusion.\n\n8. Any observable occurrence in a network or information system.\n\n9. Actions taken through the use of an information system or network that result in an actual or potentially adverse effect on an information system, network, and/or the information residing therein.\n\n10. An occurrence that actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or an information system; or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.\n\n11. An occurrence that actually or potentially jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or an information system; or constitutes a violation or imminent threat of violation of security policies, security procedures, or acceptable use policies.\n\n12. Any observable occurrence in a system.\n\n13. An occurrence that actually or potentially jeopardizes the confidentiality, integrity, or availability of a system or the information the system processes, stores, or transmits or that constitutes a violation or imminent threat of violation of security policies, security procedures, or acceptable use policies.\n\n14. Occurrence or change of a particular set of circumstances.\n\n15. Anomalous or unexpected event, set of events, condition, or situation at any time during the life cycle of a project, product, service, or system.",
  "abbreviation": "event",
  "synonyms": [
    "incident",
    "security-relevant event"
  ],
  "see_also": [
    "event",
    "incident",
    "intrusion",
    "security-relevant event"
  ],
  "references": [
    "NIST SP 800-61r3",
    "NIST SP 800-172r3 from GAO-19-128",
    "CNSSI 4009-2022",
    "CNSSI 4009-2022 from DoD 5200.28-STD",
    "CNSSI 4009-2015 from FIPS 200 (Adapted); CNSSI 4009-2022 from 44 U.S.C., Sec. 3552",
    "CNSSI 4009-2015 from NIST SP 800-61 Rev. 2",
    "CNSSI 4009-2015",
    "NIST SP 800-37 Rev. 2 from NIST SP 800-61 Rev. 2 (adapted)",
    "NIST SP 800-160 Vol. 2 [Superseded] from CNSSI 4009-2015, CNSSI 4009-2022; NIST SP 800-160 Vol. 2 Rev. 1 from CNSSI 4009-2015, CNSSI 4009-2022",
    "NIST SP 800-171 Rev. 2 [Superseded] from 44 U.S.C., Sec. 3552; NIST SP 800-37 Rev. 2 from 44 U.S.C., Sec. 3552; NIST SP 800-53 Rev. 5 from PL 113-283 (FISMA); NIST SP 800-172 [Superseded] from 44 U.S.C., Sec. 3552; NIST SP 800-172A [Superseded] from 44 U.S.C., Sec. 3552; NIST SP 800-171r3 from 44 U.S.C., Sec. 3552",
    "NIST SP 800-128 from 44 U.S.C., Sec. 3552",
    "NIST SP 800-53 Rev. 5 from NIST SP 800-61 Rev. 2 (Adapted)",
    "NIST SP 800-171 Rev. 1 [Superseded] from FIPS 200 (Adapted)",
    "NIST SP 800-160 Vol. 1 from ISO Guide 73; NIST SP 800-160v1r1 from ISO Guide 73",
    "NIST SP 800-160 Vol. 1 from ISO/IEC/IEEE 15288; NIST SP 800-160v1r1 from ISO/IEC/IEEE 15288:2015",
    "NIST CSRC Glossary"
  ],
  "url": "https://mlchart.com/terminology/cybersecurity/cyber-incident/"
}

Record 1,151 of 4,669 in Cybersecurity terminology (MLC-0102). Request the full dataset.