When a threat becomes a valid attack, it is classified as an information security
incident if [21]
• It is directed against information assets.
• It has a realistic chance of success.
• It threatens the confidentiality, integrity, or availability of information assets.