This is the second in a series of “mindset” posts where I outline how I’ve been thinking of various aspects of incident detection and response. My primary focus for these discussions will be intrusions. These are ways that security people tend to think when they are trying to identify intrusions. I’m going to list the three attitudes I’ve encountered: detection is futile, sufficient knowledge, retrospective security analysis and indicators plus retrospective security. The importance of an indicator is that it should signal the start of the analysis process.”]
Source: https://taosecurity.blogspot.com/2009/06/incident-detection-paradigms.html