Event vs. Incident
An event is an observable occurrence in an information system that actually happened at some point in time.
- A TCP/IP connection
- An email
- A user login
An incident is an adverse event in an information system - includes the significant threat of an adverse event.
- Implies harm or attempt to harm
- An attempt to gain unauthorized access
- Unwanted denial-of-service
- Changes without owner’s knowledge, instruction, or consent
