Skip to content

Threat Assessment

What is Threat Assessment?

The process of evaluating potential threats to an organization by analyzing threat actors, their capabilities, intentions, and the likelihood of attack.

Information Security

Each of these is named in at least one of the same controls as threat assessment. The number is how many controls name both.

What the standards actually require on threat assessment

Requirements naming threat assessment across 6 standards, quoted from the control text.

Chapter 2 establishes the risk-based approach to aviation security. 2.4 Threat Assessment and Risk Management - each Contracting State shall continually monitor and adjust the level of threat for civil aviation within its territory and shall establish and impl...

ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP · ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)

HKMA C-RAF Domain 1 GOVERNANCE + Domain 2 IDENTIFICATION. DOMAIN 1 GOVERNANCE (5 sub-areas): (1) CYBER RISK GOVERNANCE - board + senior management oversight + governance structure + reporting lines + delegation; board cyber-risk literacy + training;

HKMA-CRAF-Domain1-2-Governance-Identification · HKMA C-RAF Domain 1 (Governance) + Domain 2 (Identification) - Cyber Strategy, Risk Management, Asset Management, Threat Assessment

NSS-17 + NSS-42-G adopt a graded approach with Computer Security Levels (CSLs) ranging from 1 (highest, applied to safety + security critical systems) to 5 (lowest, applied to general administrative systems).

IAEA-NSS17-GradedApproach-SecurityLevels-Risk-DBT · IAEA NSS-17 - Graded Approach + Computer Security Levels + Risk-Informed Methodology + Threat Assessment + DBT Alignment + Consequence Analysis
OWASP SAMM1 control

Per OWASP SAMM v2 Design business function: secure design practices. Security Practices: (1) Threat Assessment including application threat modelling + risk assessment + (2) Security Requirements including functional security requirements + supplier security r...

OWASPSAMM-2 · Design: Threat Assessment, Security Requirements, Security Architecture

Per PAS 1192-5:2015 Security Triage clauses: triage + classify + assess threat. Requirements include (a) operate Security Triage Process to determine whether security-minded approach is required for a built asset + (b) apply Sensitivity Classification of Asset...

PASONE-1 · Security Triage Process, Asset Sensitivity Classification, and Threat Assessment

Per R155 Annex 5: threats including back-end servers + vehicle data and code + external connectivity + update process + supply chain + insider + privacy + maintain mitigations.

UNECER155-3 · Threat Assessment (Annex 5) and Risk Mitigation

Questions people ask about threat assessment

What is Threat Assessment?
The process of evaluating potential threats to an organization by analyzing threat actors, their capabilities, intentions, and the likelihood of attack.
Why is Threat Assessment important for compliance?
Threat Assessment is a key concept in Information Security. Understanding threat assessment helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Threat Assessment?
Threat Assessment appears in the requirement text of ICAO Annex 17 - Aviation Security (AVSEC), HKMA Cyber Resilience Assessment Framework (C-RAF), IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1), OWASP SAMM, PAS 1192-5:2015 - Security-Minded Approach to BIM and Digital Built Environments. Across these standards we have identified 7 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Threat Assessment?
Explore our compliance framework pages to see how threat assessment applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Threat Assessment applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.