Threat Landscape
What is Threat Landscape?
The current state of threats facing an organization or industry, including active threat actors, attack methods, and emerging attack trends.
Terms that appear alongside threat landscape
Each of these is named in at least one of the same controls as threat landscape. The number is how many controls name both.
- risk assessment 7 shared controls
- nist 7 shared controls
- cybersecurity 7 shared controls
- cyber threat 6 shared controls
- resilience 5 shared controls
- ransomware 5 shared controls
- lessons learned 5 shared controls
- compliance 5 shared controls
Frameworks that govern threat landscape
What the standards actually require on threat landscape
Requirements naming threat landscape across 6 standards, quoted from the control text.
HKMA C-RAF Domain 5 RESPONSE AND RECOVERY + Domain 6 SITUATIONAL AWARENESS. DOMAIN 5 RESPONSE AND RECOVERY (3 sub-areas): (1) INCIDENT RESPONSE PLANNING - documented IR plan + playbooks + runbooks + RACI + escalation criteria + decision trees + communication p...
HKMA-CRAF-Domain5-6-Response-Recovery-SitAwareness · HKMA C-RAF Domain 5 (Response and Recovery) + Domain 6 (Situational Awareness) - Incident Response, Recovery, Threat Landscape, Information Sharing →A Generic Threat Landscape (GTL) for the jurisdiction/sector is produced (by the relevant authorities) to inform the threat scenarios used in TIBER-EU tests; entities and providers take it into account when developing targeted threat intelligence.
TIBER-0.1 · Generic Threat Landscape →Govern covers third party cyber risk + supply chain + continuous improvement extending from the 5 functional elements per MSC-FAL.1/Circ.3/Rev.2 + Resolution MSC.428(98).
IMO-MSC-FAL-Govern-ThirdParty-SupplyChain-Manufacturer-Yard-PortFacility-IACS-E26-E27 · IMO MSC-FAL Govern - Third Party Cyber Risk + Supply Chain + Equipment Manufacturer + Yard + Port Facility + IACS UR E26/E27 + Continuous Improvement + Audit →Cybersecurity exercises + drills are mandated per FSA Cybersecurity Guidelines for Tier 2/3 institutions + coordinated industry-wide via Delta Wall + FISC. (1) Institutional Tabletop Exercises: (a) Annual minimum per FSA expectation;
JP-FSA-CYB-Cybersecurity-Exercises-Drills-Annual-Tabletop-Industry-Wide-Exercise-Delta-Wall-FSA-Coordinated-Sector · Japan FSA Cybersecurity Exercises + Drills + Annual Tabletop + Industry-Wide Exercise + Delta Wall + FSA Coordinated Sector-Wide + FISC Drills + Cross-Sector Crisis Coordination + International Exercises + Cyber Range →Use data analytics to integrate threat sources into a single real-time view of the threat landscape to move towards predicting malicious activity.
ASIC-CR-DE-2 · Data analytics for threat integration →Article 25 requires the Commission to evaluate the Regulation by 5 February 2027 (initial early assessment focused on Hub deployment and Reserve operationalisation), and to carry out a comprehensive evaluation every four years thereafter.
CSA-Art.25 · Evaluation and review (Article 25) →Questions people ask about threat landscape
What is Threat Landscape?
Why is Threat Landscape important for compliance?
Which compliance frameworks address Threat Landscape?
Where can I learn more about Threat Landscape?
See how Threat Landscape applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.