Threat Analysis
What is Threat Analysis?
The process of examining threat sources, their capabilities, motivations, and historical patterns to understand the threat environment.
Frameworks that govern threat analysis
What the standards actually require on threat analysis
Requirements naming threat analysis across 4 standards, quoted from the control text.
Identifies and assesses insider threat activity and produces the findings that start a response.
NICE-PD-WRL-005 · Insider Threat Analysis →Set the scope of all system safeguards testing and assessment broadly enough to include the automated systems and controls that the program and the current cybersecurity threat analysis indicate are necessary to identify risks and vulnerabilities that could en...
CFTC-SS-35 · Scope of Testing and Assessment →Assets and their cybersecurity properties (confidentiality, integrity, availability, authenticity, authorisation, non-repudiation) are identified as the basis for threat analysis.
21434-15.3 · Asset Identification (TARA Step 1) →Security Dimension 7 Availability per X.805 Clause 6.7: Availability ensures that there is no denial of authorized access to network elements + stored information + information flows + services and applications due to events impacting the network.
X805-Dim7-Availability-Network-Resources-Information-Authorized-Access-No-Service-Denial · ITU-T X.805 Security Dimension 7 - Availability + Network Resources + Information Accessible to Authorized Users + Denial-of-Service Prevention + Resilience + Redundancy + Disaster Recovery + Business Continuity + DDoS Mitigation →Questions people ask about threat analysis
What is Threat Analysis?
Why is Threat Analysis important for compliance?
Which compliance frameworks address Threat Analysis?
Where can I learn more about Threat Analysis?
See how Threat Analysis applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.