Threat
Definition
A potential cause of an unwanted incident that could harm an asset. Threats may be natural (flood, fire), environmental (power failure), human accidental (misconfiguration), or human deliberate (ransomware, insider theft). A threat alone does not constitute risk; it must be paired with a vulnerability and a potential impact.
- Field
- Information security, risk management
- Definition
- Potential cause of an unwanted incident that could harm an asset
- Categories
- Natural, environmental, human accidental, human deliberate
- Not the same as
- Risk, which needs a vulnerability and potential impact too
Common questions
Why isn't a threat by itself enough to justify a security control?+
A threat only becomes a meaningful risk when it can act on an actual vulnerability and produce a real impact on an asset. A flood is a threat everywhere, but it only creates risk for assets that are physically exposed to flooding, which is why risk assessments pair threats with vulnerability and impact analysis.
How do human accidental and human deliberate threats differ in how they are addressed?+
Accidental threats, like a misconfiguration, are typically countered with training, change control, and automated checks, while deliberate threats need controls aimed at an intentional adversary, such as access restrictions, monitoring, and incident response capability, since the attacker will actively try to work around defences.
Related terms
- Vulnerability
- A weakness in an asset or in a control protecting that asset, which a threat could exploit to cause harm. Examples: an...
- Asset Inventory (Asset Register)
- A structured record listing every information asset in scope, together with its owner, custodian, physical or logical location, classification level, criticality rating,...
- Asset Owner
- The person or role accountable for ensuring an asset is appropriately classified, protected, and reviewed. The owner is typically a business manager...
- Availability
- The property that systems and data are accessible to authorised users when needed. Protected by redundancy, backup, failover, and incident response capabilities....
- Classification Tier
- A label assigned to an asset or data type indicating its sensitivity and the handling rules that apply. Common tiers are Public,...
- Confidentiality
- The property that information is not disclosed to unauthorised individuals, processes, or devices. Protected by access controls, encryption, and need-to-know policies. Breached...
- Information Asset
- Anything that has value to the organisation by virtue of the information it contains or the information function it performs. Includes data,...
- Integrity
- The property that information is accurate, complete, and has not been modified without authorisation. Protected by cryptographic hashing, digital signatures, and change...
- Non-Repudiation
- The property that a party cannot deny having performed an action. Provided by digital signatures, timestamped audit logs, and certified delivery receipts....
Explained in these topics
- The CIA Triad and Security FundamentalsAny potential event, actor, or circumstance that could cause harm to an information asset. Examples include ransomware groups, insider misuse, power failures,...
- Risk Identification and Asset Classification