Threat Management
What is Threat Management?
The ongoing process of identifying, evaluating, and responding to cybersecurity threats facing an organization.
Frameworks that govern threat management
What the standards actually require on threat management
Requirements naming threat management across 3 standards, quoted from the control text.
Maintain threat intelligence, vulnerability management, penetration testing, and red team capabilities to identify and remediate weaknesses in a timely manner.
SIG-P-01 · Threat Management →Conduct regular vulnerability assessments and threat assessments on the CII, remediate identified vulnerabilities within prescribed timeframes, and track threat intelligence relevant to the CII sector.
SCA-VM-1 · Vulnerability and Threat Management for CII →The entity must manage the personnel security lifecycle, including onboarding, ongoing suitability and insider-threat management, and offboarding (removal of access and return of assets).
DISP-PERS-LIFECYCLE · Onboarding, offboarding and ongoing suitability →Questions people ask about threat management
What is Threat Management?
Why is Threat Management important for compliance?
Which compliance frameworks address Threat Management?
Where can I learn more about Threat Management?
See how Threat Management applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.