The U.S. Department of
Homeland Security (DHS) defines a computer security incident as a real
or potential violation of an explicit or implied policy regarding information.
The DHS has five incident types, based on incident outcomes: (1) increased
access beyond authorization; (2) information disclosure; (3) information
corruption; (4) Denial of Service (DoS);
and (5) resource theft. The DHS notes that actual incidents often fall into
multiple categories. For example, a Website defacement can involve increased
access beyond authorization and information corruption, and a system compromise
can involve increased access beyond authorization, information disclosure, and
resource theft.
See Also:
Denial of Service (DoS); Department of Homeland Security (DHS); Exploit;
Vulnerabilities of Computers.
U.S. Department of Homeland Security. DHS Organization. [Online, 2004.] U.S.
Department of Homeland Security Website. http://www.dhs.gov/dhspublic/theme_
home1.jsp.