An occurrence that actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.
Sources:
CNSSI 4009-2022
under incident
from
44 U.S.C., Sec. 3552
An occurrence (e.g., an auditable event or flag) considered to have potential security implications to the system or its environment that may require further action (noting, investigating, or reacting).
Sources:
CNSSI 4009-2022
under security-relevant event
Any event that attempts to change the security state of the system, (e.g., change discretionary access controls, change the security level of the subject, change user password, etc.). Also, any event that attempts to violate the security policy of the system, (e.g., too many attempts to login, attempts to violate the mandatory access control limits of a device, attempts to downgrade a file, etc.).
Sources:
CNSSI 4009-2022
under security-relevant event
from
DoD 5200.28-STD
Occurrence or change of a particular set of circumstances.
Sources:
NIST SP 800-160v1r1
under event
from
ISO Guide 73
Anomalous or unexpected event, set of events, condition, or situation at any time during the life cycle of a project, product, service, or system.
Sources:
NIST SP 800-160v1r1
under incident
from
ISO/IEC/IEEE 15288:2015
Any observable occurrence in a network or information system.
Sources:
NIST SP 800-37 Rev. 2
under event
Actions taken through the use of an information system or network that result in an actual or potentially adverse effect on an information system, network, and/or the information residing therein.
Sources:
NIST SP 800-160 Vol. 2 Rev. 1
from
CNSSI 4009-2022
An occurrence that actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or an information system; or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.
Sources:
NIST SP 800-171r3
under incident
from
44 U.S.C., Sec. 3552
NIST SP 800-37 Rev. 2
under incident
from
44 U.S.C., Sec. 3552
NIST SP 800-53 Rev. 5
under incident
from
PL 113-283 (FISMA)
An occurrence that actually or potentially jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or an information system; or constitutes a violation or imminent threat of violation of security policies, security procedures, or acceptable use policies.
Sources:
NIST SP 800-128
under incident
from
44 U.S.C., Sec. 3552
Any observable occurrence in a system.
Sources:
NIST SP 800-53 Rev. 5
under event
Any observable occurrence involving computing assets, including physical and virtual platforms, networks, services, and cloud environments.
Sources:
NIST SP 800-61r3
under event
An occurrence that actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or an information system or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.
Sources:
NIST SP 800-172r3
under incident
from
GAO-19-128