4. Incidents, audits and improvement
Events, incidents, and why you report both
The language here matters, because it determines what gets reported.
Event versus incident
A security event is any observed occurrence that might be relevant to security: a phishing email, a login alert you did not trigger, a door lock that is not latching, a system behaving oddly. Many events turn out to be harmless.
A security incident is an event, or a series of events, that has actually compromised, or has a significant chance of compromising, information security: a mailbox taken over, a laptop stolen, data sent to the wrong recipient, ransomware detected, sensitive papers gone from a desk.
The distinction matters because deciding which is which is not your job. Your job is to report events and let the people with the full picture assess them. A single odd login is an event. Fifty of them across the company is an attack, and nobody sees that pattern unless individuals report their one odd login.
Report weaknesses too
ISO 27001 expects staff to report not just things that have gone wrong, but weaknesses: ways things could go wrong. The broken door lock, the shared password everyone quietly uses, the export function that includes far more customer data than it should. Reporting a weakness before it is exploited is the cheapest security win there is.
Promptly means promptly
Speed matters enormously in incident response. A phishing email reported within minutes lets IT block the sender and warn others before more people click. A compromised account reported within the hour can be locked before data leaves. The same reports made next week are archaeology. So report as soon as you notice, through your organisation's route, whether that is a helpdesk, a security team address, or a report button in your email client.
Two rules make reporting work. First, honest mistakes reported promptly are treated as what they are: the system working. The person who clicks a phishing link and reports it immediately has done the right thing. Second, when in doubt, report. Nobody in a functioning ISMS is criticised for a false alarm.
› Course contents
What ISO 27001 is
Policies and your responsibilities
Everyday controls
Incidents, audits and improvement