Skip to content

Threat Detection

What is Threat Detection?

The process and technology used to identify malicious activity, policy violations, and other security threats within an organization's environment.

Information Security

Each of these is named in at least one of the same controls as threat detection. The number is how many controls name both.

What the standards actually require on threat detection

Requirements naming threat detection across 6 standards, quoted from the control text.

Define and implement a logging, threat detection and incident response strategy so threats are detected and remediated rapidly and compliance requirements for logging are met.

ASBv3-GS-7 · Define and implement logging, threat detection and incident response strategy

Lloyds MS11.7 Threat Detection and Security Monitoring - 24/7/365 Security Operations Centre (SOC) capability internal or via Managed Security Service Provider (MSSP) + Security Information and Event Management (SIEM) covering identity + network + endpoint + c...

LLOYDS-MS11-Threat-Detection-Security-Monitoring-Email-Phishing-Defences-MS11-7-12-SOC-EDR-XDR-SIEM · Lloyds MS11 Threat Detection + Security Monitoring + Email + Phishing + MS11.7-12

Deploy runtime threat detection that monitors process activity, file changes, and network behavior inside containers. Tune detections to the workload baseline and integrate alerts with the SOC.

SP800-190-3.17 · Runtime Threat Detection

Chapter 4 establishes preventive security measures starting with access control + personnel security. 4.1 Measures Relating to Access Control - each State shall establish + implement measures to prevent unauthorised persons + vehicles + items from gaining acce...

ICAO-ANX17-Chap4-AccessControl-AirsideRestricted-Personnel-Background · ICAO Annex 17 Chapter 4 - Access Control + Airside + Security Restricted Area + Personnel Background Checks + Vetting

Article 32 establishes the ADVANCED CYBERSECURITY CONTROLS that critical-impact entities must implement IN ADDITION TO the Article 30 minimum controls.

NCCS-Art.32_33_34 · Advanced cybersecurity controls (NCCS Articles 32-34) - for critical-impact entities

Personnel security + insider threat for aviation cybersecurity covers: (a) FAA Order 1370.123A insider threat program for FAA employees + contractors;

FAA-CSA-Personnel · Personnel Security Training and Insider Threat

Questions people ask about threat detection

What is Threat Detection?
The process and technology used to identify malicious activity, policy violations, and other security threats within an organization's environment.
Why is Threat Detection important for compliance?
Threat Detection is a key concept in Information Security. Understanding threat detection helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Threat Detection?
Threat Detection appears in the requirement text of Azure Security Benchmark, Lloyd's Minimum Standards - Cyber Security, NIST SP 800-190, ICAO Annex 17 - Aviation Security (AVSEC), EU Network Code on Cybersecurity for the Electricity Sector. Across these standards we have identified 11 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Threat Detection?
Explore our compliance framework pages to see how threat detection applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Threat Detection applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.