Describe both the threat source and the event being considered. This keeps a broad label such as “cyberattack” from substituting for a scenario that can actually be assessed.
Threat
A threat is any circumstance or event with the potential to adversely impact organizational operations and assets, individuals, other organizations, or the Nation through an information system via unauthorized access, destruction, disclosure, or modification of information, and/or denial of service. Threat events are caused by threat sources.
Threat Source
A threat source is characterized as:
- The intent and method targeted at the exploitation of a vulnerability; or
- A situation and method that may accidentally exploit a vulnerability.
Various taxonomies of threat sources have been developed. Review the reference sources and workspace-configured choices in CSFaaS before classifying a scenario. Maintain additional catalogue entries where your permissions and the selected catalogue allow it.
Threat Scenario
Risk models vary in the level of detail and complexity used to identify threat events. When threat events are identified with greater specificity, threat scenarios can be modeled, developed, and analyzed.
A threat scenario consists of discrete threat events attributed to one or more threat sources, ordered chronologically, that result in adverse effects.
(Source: NIST SP 800-30 Rev. 1)