Threats #
Objective #
The Threats menu maintains the catalog of events likely to exploit a vulnerability. Main fields: name, description, category, source and severity.
Usage #
Risk manager creates, modifies or deletes; all authorized users read. Search and filter before creating a duplicate. Prefer observable wording, a dated source and documented severity.
Relationships #
A threat is associated with a risk scenario with an asset and vulnerabilities. Removal of a used threat may be refused or require processing of links.
Description of fields #
The name describes the event, the description specifies operating procedure and consequences, the category facilitates grouping, the source indicates the origin of the information and the severity gives an initial benchmark.
Complete procedure #
Look for synonyms, create a reusable generic label, cite a non-sensitive source then choose a justified severity. Then associate the threat with the relevant scenarios rather than duplicating one threat per asset.
Example #
“Credential compromise through phishing” describes an event; “lack of MFA” is a vulnerability, not a threat.
Common errors #
Avoid wording that mixes threat, weakness and consequence. An obsolete source or unjustified severity should trigger a review, not a duplication.