Governance Risk Compliance
脅威評価
A structured process for identifying, evaluating, and prioritizing potential threats to an organization's assets, operations, or individuals.
Quick answer: A structured process for identifying, evaluating, and prioritizing potential threats to an organization's assets, operations, or individuals.
This term page is part of the Protermify Cybersecurity glossary and is published as static HTML for fast indexing and clear language coverage.
Definition
A structured process for identifying, evaluating, and prioritizing potential threats to an organization's assets, operations, or individuals.
Operational example
An annual threat assessment is conducted to identify new adversarial tactics and inform the organization's risk mitigation plan.
Localized example
新たな敵対的戦術を特定し、組織のリスク低減計画に役立てるため、毎年脅威評価が実施されます。
Definition language
English reference definition
Source
ISO 27001, NIST Cybersecurity Framework, MITRE ATT&CK
Exam relevance
- CISSP
- CompTIA Security+
- CEH
Target audience
- SOC Analysts
- Security Engineers
- Incident Responders