enisaeu / Reference-Security-Incident-Taxonomy-Task-Force

This repository hosts files relating to the TF-CSIRT Reference Security Incident Taxonomy Working Group.
Creative Commons Zero v1.0 Universal
64 stars 33 forks source link

Improve description for sabotage #105

Closed INCIBE-CERT closed 3 years ago

INCIBE-CERT commented 3 years ago

Inspired by the discussion during 2021-05-26 meeting sprang by PR #98

Description tries to avoid including into sabotage actions like udp flood saturating the bandwidth since in the later case no component is damaged, and the system would recover by themselves, whereas a sabotage would generally require some manual recovery steps (notwithstanding tools able to automatically restore from certain sabotage actions and non-sabotages that end up requiring some manual action).

Adding "bomb threats" to convey the meaning of "terrorism" of PR #98 in a more neutral way.

Dropping the adjective from "malicious arson" since arson already implies malicious intent.