Threat Detection
What is Threat Detection?
The process and technology used to identify malicious activity, policy violations, and other security threats within an organization's environment.
Terms that appear alongside threat detection
Each of these is named in at least one of the same controls as threat detection. The number is how many controls name both.
- insider threat 6 shared controls
- threat intelligence 5 shared controls
- incident response 4 shared controls
- cybersecurity 4 shared controls
- integrity 4 shared controls
- compliance 4 shared controls
- phishing 3 shared controls
- security monitoring 3 shared controls
Frameworks that govern threat detection
What the standards actually require on threat detection
Requirements naming threat detection across 6 standards, quoted from the control text.
Define and implement a logging, threat detection and incident response strategy so threats are detected and remediated rapidly and compliance requirements for logging are met.
ASBv3-GS-7 · Define and implement logging, threat detection and incident response strategy →Lloyds MS11.7 Threat Detection and Security Monitoring - 24/7/365 Security Operations Centre (SOC) capability internal or via Managed Security Service Provider (MSSP) + Security Information and Event Management (SIEM) covering identity + network + endpoint + c...
LLOYDS-MS11-Threat-Detection-Security-Monitoring-Email-Phishing-Defences-MS11-7-12-SOC-EDR-XDR-SIEM · Lloyds MS11 Threat Detection + Security Monitoring + Email + Phishing + MS11.7-12 →Deploy runtime threat detection that monitors process activity, file changes, and network behavior inside containers. Tune detections to the workload baseline and integrate alerts with the SOC.
SP800-190-3.17 · Runtime Threat Detection →Chapter 4 establishes preventive security measures starting with access control + personnel security. 4.1 Measures Relating to Access Control - each State shall establish + implement measures to prevent unauthorised persons + vehicles + items from gaining acce...
ICAO-ANX17-Chap4-AccessControl-AirsideRestricted-Personnel-Background · ICAO Annex 17 Chapter 4 - Access Control + Airside + Security Restricted Area + Personnel Background Checks + Vetting →Article 32 establishes the ADVANCED CYBERSECURITY CONTROLS that critical-impact entities must implement IN ADDITION TO the Article 30 minimum controls.
NCCS-Art.32_33_34 · Advanced cybersecurity controls (NCCS Articles 32-34) - for critical-impact entities →Personnel security + insider threat for aviation cybersecurity covers: (a) FAA Order 1370.123A insider threat program for FAA employees + contractors;
FAA-CSA-Personnel · Personnel Security Training and Insider Threat →Questions people ask about threat detection
What is Threat Detection?
Why is Threat Detection important for compliance?
Which compliance frameworks address Threat Detection?
Where can I learn more about Threat Detection?
See how Threat Detection applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.