Level
4
Extreme
:
Full alert
This condition applies when extreme global network incident activity is in progress. Implementation of measures in this condition for more than a short period probably will create hardship and affect normal operations.
Level
3
High
:
Known threat
This condition applies when an isolated threat to the computing infrastructure is currently underway or when malicious code reaches a severe risk rating. Under this condition, increased monitoring is necessary.
Level
2
Elevated
:
Increased alertness
This condition applies when knowledge or the expectation of attack activity is present, without specific events occurring or when malicious code reaches a moderate risk rating.
Level
1
Normal
:
Basic network posture
This condition applies when there is no discernible network incident activity and no malicious code activity with a moderate or severe risk rating.