Threat Assessment
What is Threat Assessment?
The process of evaluating potential threats to an organization by analyzing threat actors, their capabilities, intentions, and the likelihood of attack.
Terms that appear alongside threat assessment
Each of these is named in at least one of the same controls as threat assessment. The number is how many controls name both.
- vulnerability 6 shared controls
- risk assessment 5 shared controls
- vulnerability assessment 4 shared controls
- threat intelligence 3 shared controls
- insider threat 3 shared controls
- risk treatment 3 shared controls
- change management 2 shared controls
- malware 2 shared controls
Frameworks that govern threat assessment
What the standards actually require on threat assessment
Requirements naming threat assessment across 6 standards, quoted from the control text.
Chapter 2 establishes the risk-based approach to aviation security. 2.4 Threat Assessment and Risk Management - each Contracting State shall continually monitor and adjust the level of threat for civil aviation within its territory and shall establish and impl...
ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP · ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18) →HKMA C-RAF Domain 1 GOVERNANCE + Domain 2 IDENTIFICATION. DOMAIN 1 GOVERNANCE (5 sub-areas): (1) CYBER RISK GOVERNANCE - board + senior management oversight + governance structure + reporting lines + delegation; board cyber-risk literacy + training;
HKMA-CRAF-Domain1-2-Governance-Identification · HKMA C-RAF Domain 1 (Governance) + Domain 2 (Identification) - Cyber Strategy, Risk Management, Asset Management, Threat Assessment →NSS-17 + NSS-42-G adopt a graded approach with Computer Security Levels (CSLs) ranging from 1 (highest, applied to safety + security critical systems) to 5 (lowest, applied to general administrative systems).
IAEA-NSS17-GradedApproach-SecurityLevels-Risk-DBT · IAEA NSS-17 - Graded Approach + Computer Security Levels + Risk-Informed Methodology + Threat Assessment + DBT Alignment + Consequence Analysis →Per OWASP SAMM v2 Design business function: secure design practices. Security Practices: (1) Threat Assessment including application threat modelling + risk assessment + (2) Security Requirements including functional security requirements + supplier security r...
OWASPSAMM-2 · Design: Threat Assessment, Security Requirements, Security Architecture →Per PAS 1192-5:2015 Security Triage clauses: triage + classify + assess threat. Requirements include (a) operate Security Triage Process to determine whether security-minded approach is required for a built asset + (b) apply Sensitivity Classification of Asset...
PASONE-1 · Security Triage Process, Asset Sensitivity Classification, and Threat Assessment →Per R155 Annex 5: threats including back-end servers + vehicle data and code + external connectivity + update process + supply chain + insider + privacy + maintain mitigations.
UNECER155-3 · Threat Assessment (Annex 5) and Risk Mitigation →Questions people ask about threat assessment
What is Threat Assessment?
Why is Threat Assessment important for compliance?
Which compliance frameworks address Threat Assessment?
Where can I learn more about Threat Assessment?
See how Threat Assessment applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.