178k views
0 votes
Alerts can be viewed as a unit of investigations
a) True
b) False

1 Answer

6 votes

Final answer:

Alerts are indeed seen as the starting point for investigations in environments like info security centers, and handling them correctly is vital for accurate incident response.

Step-by-step explanation:

The statement that alerts can be viewed as a unit of investigations is true. Alerts in the context of an information security center or any similar environment are often the starting point for investigating potential security breaches or issues. As demonstrated in the study by Bruno & Abrahão (2012), the decision-making process in response to such alerts is crucial and can be affected by the cognitive load on the personnel. The study's findings suggested that an increase in cognitive demand led to more frequent misclassification of incidents, resulting in false alarms but not in an increased rate of missing actual threats. This is significant as it affects the reliability of security measures and indicates the need for efficient and accurate alert management systems to ensure proper investigation and response to potential security breaches, such as the well-known incident that affected Target in 2013.

User Aditya Kamath
by
8.1k points