SEVERITY CONFIRMATION NEEDED FOR JUST ONLY OBTAIN EARLY INDICATORS OF AN OCCURENCE/$
The correct classification for obtaining early indicators of an occurrence is Low (or Informational / Notice).
Severity Breakdown
| Severity Level | Characteristic Criteria | Fit for Early Indicators |
|---|---|---|
| Low / Informational | Operational awareness, early warning signals, potential trend shifts, pre-incident logs. | Exact Match. Early indicators reflect potential conditions before impact or actual occurrence. |
| Medium | Measurable impact, performance degradation, minor service disruption, localized risk. | No. Early indicators alone do not confirm impact or active disruption. |
| High | Critical system compromise, significant downtime, major data risk, severe failure. | No. High severity requires active, high-impact events or confirmed severe breaches. |
Contextual Considerations
- Security Monitoring (SOC / SIEM): Early indicators (e.g., unusual login velocity, minor scan activity) are triaged as Low / Informational until correlated with secondary evidence.
- Risk Management & Auditing: Key Risk Indicators (KRIs) serving as early warnings are categorized under Low Severity (Watchlist / Observation) until tolerance thresholds are crossed.
- Incident Response: Early indicators serve to trigger heightened monitoring or preventive controls, not an emergency escalation pathway.
Comments
Post a Comment