What is the baseline definition of a ‘security event/incident’?
Both the term ‘event’ and ‘incident’ are used in section 2.3 of the CoCo, but the term ‘incident’ is what is important in this section. An event is an observable change to the normal expected behaviour of a system, whereas an incident is an event attributable to a human course and signifies malicious intent. To understand better the area of security incident management, refer to BS ISO /IEC 27002 (formerly 17799).