A firewall logs 10,000 blocked connection attempts daily. A phishing email reaches an employee inbox. An attacker exfiltrates customer records. All three are security-related, but only one is an incident requiring formal response. Distinguishing events from incidents, and knowing how to test whether an organization responded properly, is core ISC territory.
AICPA Representative Tasks (verbatim). 1. Remembering & Understanding, Recall the differences between security/cybersecurity events and incidents. 2. Remembering & Understanding, Explain the purpose of insurance as a mitigation strategy for a security incident or data breach. 3. Remembering & Understanding, Summarize contents commonly included in incident response plans (e.g., roles, responsibilities, methods, steps, timelines). 4. Application, Perform procedures to test whether the entity responded to cybersecurity incidents in accordance with the incident response plan.
HIGH-FREQUENCY: The exam tests whether you can distinguish routine events from reportable incidents.
A security event is any observable occurrence in an information system. Events are neutral: they include successful logins, failed login attempts, firewall blocks, system reboots, and configuration changes. Most events are benign or expected.
Common mistakes
- Treating all security events as incidents. Not every alert requires IRP activation. The distinction matters for resource allocation and documentation burden. The IRP should define thresholds for escalation from event to incident.
- Assuming cyber insurance covers all breach costs. Policy limits, retentions, and exclusions significantly constrain coverage. Known vulnerabilities, sanctions violations, and nation-state attacks are commonly excluded or contested.
- Failing to preserve forensic evidence. Rushing to restore systems destroys evidence needed for root cause analysis, legal action, and regulatory defense. The IRP must mandate imaging before eradication.
Bottom line
- Security event = any observable occurrence in a system; security incident = an event that actually or potentially compromises confidentiality, integrity, or availability, requiring response.
- IRPs must specify roles by name (not just title) with designated backups, plus escalation paths, communication protocols, containment steps, evidence preservation, recovery procedures, and post-incident review timelines.
- IRP phases follow Containment, then Eradication, then Recovery; forensic imaging must occur before eradication to preserve evidence.
- Cyber insurance transfers residual breach-cost risk (forensics, notification, legal defense, regulatory fines, business interruption) but excludes intentional acts, known vulnerabilities, war/terrorism, and sanctions violations.
Exam shortcut
Event vs. Incident quick test: Ask "Does this require formal response and documentation beyond logging?" If yes, it is an incident. If the system handled it automatically (blocked, logged, moved on), it is an event. Insurance coverage check: Assume exclusions apply. Known vulnerability + no patch = likely denied. Sanctioned actor = definitely denied. Always verify policy terms before assuming coverage.
The full lesson (about 5,845 words, 39 min read) adds 10 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- II.D1
Browse all free CPA ISC lessons or jump into free CPA ISC practice questions.