Governance Risk Compliance
威胁评估
A structured process for identifying, evaluating, and prioritizing potential threats to an organization's assets, operations, or individuals.
Quick answer: A structured process for identifying, evaluating, and prioritizing potential threats to an organization's assets, operations, or individuals.
This term page is part of the Protermify Cybersecurity glossary and is published as static HTML for fast indexing and clear language coverage.
Definition
A structured process for identifying, evaluating, and prioritizing potential threats to an organization's assets, operations, or individuals.
Operational example
An annual threat assessment is conducted to identify new adversarial tactics and inform the organization's risk mitigation plan.
Localized example
每年都会进行威胁评估,以识别新的对手策略并完善组织的风险缓解计划。
Definition language
English reference definition
Source
ISO 27001, NIST Cybersecurity Framework, MITRE ATT&CK
Exam relevance
- CISSP
- CompTIA Security+
- CEH
Target audience
- SOC Analysts
- Security Engineers
- Incident Responders