Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

A  |  B  |  C  |  D  |  E  |  F  |  G  |  H  |  I  |  J  |  K  |  L  |  M  |  N  |  O  |  P  |  Q  |  R  |  S  |  T  |  U  |  V  |  W  |  X  |  Y  |  Z

cyber incident

Abbreviations / Acronyms / Synonyms:

event
incident
security-relevant event

Definitions:

  An occurrence that actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.
Sources:
CNSSI 4009-2022 under incident from 44 U.S.C., Sec. 3552

  An occurrence (e.g., an auditable event or flag) considered to have potential security implications to the system or its environment that may require further action (noting, investigating, or reacting).
Sources:
CNSSI 4009-2022 under security-relevant event

  Any event that attempts to change the security state of the system, (e.g., change discretionary access controls, change the security level of the subject, change user password, etc.). Also, any event that attempts to violate the security policy of the system, (e.g., too many attempts to login, attempts to violate the mandatory access control limits of a device, attempts to downgrade a file, etc.).
Sources:
CNSSI 4009-2022 under security-relevant event from DoD 5200.28-STD

  Occurrence or change of a particular set of circumstances.
Sources:
NIST SP 800-160v1r1 under event from ISO Guide 73

  Anomalous or unexpected event, set of events, condition, or situation at any time during the life cycle of a project, product, service, or system.
Sources:
NIST SP 800-160v1r1 under incident from ISO/IEC/IEEE 15288:2015

  Any observable occurrence in a network or information system.
Sources:
NIST SP 800-37 Rev. 2 under event

  Actions taken through the use of an information system or network that result in an actual or potentially adverse effect on an information system, network, and/or the information residing therein.
Sources:
NIST SP 800-160 Vol. 2 Rev. 1 from CNSSI 4009-2022

  An occurrence that actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or an information system; or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.
Sources:
NIST SP 800-171r3 under incident from 44 U.S.C., Sec. 3552
NIST SP 800-37 Rev. 2 under incident from 44 U.S.C., Sec. 3552
NIST SP 800-53 Rev. 5 under incident from PL 113-283 (FISMA)

  An occurrence that actually or potentially jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or an information system; or constitutes a violation or imminent threat of violation of security policies, security procedures, or acceptable use policies.
Sources:
NIST SP 800-128 under incident from 44 U.S.C., Sec. 3552

  Any observable occurrence in a system.
Sources:
NIST SP 800-53 Rev. 5 under event

  Any observable occurrence involving computing assets, including physical and virtual platforms, networks, services, and cloud environments.
Sources:
NIST SP 800-61r3 under event

  An occurrence that actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or an information system or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.
Sources:
NIST SP 800-172r3 under incident from GAO-19-128