security-relevant event
Term · Cybersecurity · MLC-T-CYB-003857
1. An occurrence (e.g., an auditable event or flag) considered to have potential security implications to the system or its environment that may require further action (noting, investigating, or reacting).
2. Any event that attempts to change the security state of the system, (e.g., change discretionary access controls, change the security level of the subject, change user password, etc.). Also, any event that attempts to violate the security policy of the system, (e.g., too many attempts to login, attempts to violate the mandatory access control limits of a device, attempts to downgrade a file, etc.).
3. Actions taken through the use of an information system or network that result in an actual or potentially adverse effect on an information system, network, and/or the information residing therein. See incident. See also event, security-relevant event, and intrusion.
4. Actions taken through the use of an information system or network that result in an actual or potentially adverse effect on an information system, network, and/or the information residing therein.
5. Any event that attempts to change the security state of the system (e.g., change access controls, change the security level of a user, change a user password). Also, any event that attempts to violate the security policy of the system (e.g., too many logon attempts).
| Identifier | MLC-T-CYB-003857 |
|---|---|
| Field | Cybersecurity |
| Synonyms | cyber incident |
| References | CNSSI 4009-2022; CNSSI 4009-2022 from DoD 5200.28-STD; CNSSI 4009-2015; NIST SP 800-160 Vol. 2 [Superseded] from CNSSI 4009-2015, CNSSI 4009-2022; NIST SP 800-160 Vol. 2 Rev. 1 from CNSSI 4009-2015, CNSSI 4009-2022; NISTIR 5153 from DoD 5200.28-STD; NIST CSRC Glossary |
| See also | cyber incident; event |
Record as JSON
{
"id": "MLC-T-CYB-003857",
"term": "security-relevant event",
"field": "Cybersecurity",
"definition": "1. An occurrence (e.g., an auditable event or flag) considered to have potential security implications to the system or its environment that may require further action (noting, investigating, or reacting).\n\n2. Any event that attempts to change the security state of the system, (e.g., change discretionary access controls, change the security level of the subject, change user password, etc.). Also, any event that attempts to violate the security policy of the system, (e.g., too many attempts to login, attempts to violate the mandatory access control limits of a device, attempts to downgrade a file, etc.).\n\n3. Actions taken through the use of an information system or network that result in an actual or potentially adverse effect on an information system, network, and/or the information residing therein. See incident. See also event, security-relevant event, and intrusion.\n\n4. Actions taken through the use of an information system or network that result in an actual or potentially adverse effect on an information system, network, and/or the information residing therein.\n\n5. Any event that attempts to change the security state of the system (e.g., change access controls, change the security level of a user, change a user password). Also, any event that attempts to violate the security policy of the system (e.g., too many logon attempts).",
"synonyms": [
"cyber incident"
],
"see_also": [
"cyber incident",
"event"
],
"references": [
"CNSSI 4009-2022",
"CNSSI 4009-2022 from DoD 5200.28-STD",
"CNSSI 4009-2015",
"NIST SP 800-160 Vol. 2 [Superseded] from CNSSI 4009-2015, CNSSI 4009-2022; NIST SP 800-160 Vol. 2 Rev. 1 from CNSSI 4009-2015, CNSSI 4009-2022",
"NISTIR 5153 from DoD 5200.28-STD",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/security-relevant-event/"
}
Record 3,857 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.