home/glossary/threat

threat

nounid 4417·updated May 12, 2026
candidate

Any circumstance or event with the potential to adversely impact organizational operations, organizational assets, individuals, other organizations, or the Nation through a system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service. [21]

polysemous

Attested in

No recorded attestations. They are written when an MWE tagging stage is completed, stamped with the pack version and the document’s digest.

Classifications

Entity Type

Threat0%rule-basedmulti_axis_classifier_low_confidence.v1

Sensitivity

80%llm-generatedllm:claude-haiku-4-5

Information Class

85%llm-generatedllm:claude-haiku-4-5

Variants

synonym
menaceterror
alternatephrasing
Threat
plural
threats
possessive
threat's
pluralpossessive
threats'

Framework definitions

SANS Glossary of Security Terms1 senseview framework →
§1
A potential for violation of security, which exists when there is a circumstance, capability, action, or event that could breach security and cause harm.
National Initiative for Cybersecurity Careers and Studies (NICCS) Cybersecurity Lexicon1 senseview framework →
§1 · extended_definition_available
A circumstance or event that has or indicates the potential to exploit vulnerabilities and to adversely impact (create adverse consequences for) organizational operations, organizational assets (including information and information systems), individuals, other organizations, or society.
ISACA Cybersecurity Glossary1 senseview framework →
§1
Anything (e.g., object, substance, human) that is capable of acting against an asset in a manner that can result in harm Scope Note: A potential cause of an unwanted incident (ISO/IEC 13335)
NIST Cybersecurity Framework1 senseview framework →
§1
Any circumstance or event with the potential to adversely impact organizational operations (including mission, functions, image, or reputation), organizational assets, or individuals through an information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service. Also, the potential for a threat-source to successfully exploit a particular information system vulnerability.
FFIEC Cybersecurity Assessment Tool, Baseline, May 20171 senseview framework →
§1
Any circumstance or event with the potential to adversely impact organizational operations (including mission, functions, image, or reputation), organizational assets, or individuals through an information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service. Also, the potential for a threat-source to successfully exploit a particular information system vulnerability.
FFIEC IT Examination Handbook - Audit, April 20121 senseview framework →
§1
Any circumstance or event with the potential to adversely impact organizational operations (including mission, functions, image, or reputation), organizational assets, or individuals through an information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service. Also, the potential for a threat-source to successfully exploit a particular information system vulnerability.
NERC CIP-010-2 (Config Change Management & Vulnerability) v21 senseview framework →
§1
Any circumstance or event with the potential to adversely impact organizational operations (including mission, functions, image, or reputation), organizational assets, or individuals through an information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service. Also, the potential for a threat-source to successfully exploit a particular information system vulnerability.
NERC CIP-007-6 (System Security Management) v61 senseview framework →
§1
Any circumstance or event with the potential to adversely impact organizational operations (including mission, functions, image, or reputation), organizational assets, or individuals through an information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service. Also, the potential for a threat-source to successfully exploit a particular information system vulnerability.
CPMI-IOSCO Guidance on Cyber Resilience for Financial Market Infrastructures1 senseview framework →
§1
A circumstance or event that has or indicates the potential to exploit vulnerabilities and to adversely impact (create adverse consequences for) organisational operations, organisational assets (including information and information systems), individuals, other organisations or society in general.
NISTIR 7298: Glossary of Key Information Security Terms, Revision 23 sensesview framework →
§1
Any circumstance or event with the potential to adversely impact organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, or the Nation through an information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service.
§2 · sense_2_pending_review
The potential source of an adverse event.
§3 · sense_3_pending_review
Any circumstance or event with the potential to adversely impact organizational operations (including mission, functions, image, or reputation), organizational assets, or individuals through an information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service. Also, the potential for a threat-source to successfully exploit a particular information system vulnerability.
CNSSI-4009 (Glossary of Information Assurance Terms)1 senseview framework →
§1
Any circumstance or event with the potential to adversely impact organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, or the Nation through an information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service.
NIST SP 800-531 senseview framework →
§1
Any circumstance or event with the potential to adversely impact organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, or the Nation through an information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service.
NIST SP 800-53A1 senseview framework →
§1
Any circumstance or event with the potential to adversely impact organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, or the Nation through an information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service.
NIST SP 800-371 senseview framework →
§1
Any circumstance or event with the potential to adversely impact organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, or the Nation through an information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service.
FIPS PUB 2001 senseview framework →
§1
Any circumstance or event with the potential to adversely impact organizational operations (including mission, functions, image, or reputation), organizational assets, or individuals through an information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service. Also, the potential for a threat-source to successfully exploit a particular information system vulnerability.
NIST SP 800-601 senseview framework →
§1
Any circumstance or event with the potential to adversely impact organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, or the Nation through an information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service.
NIST SP 800-271 senseview framework →
§1
Any circumstance or event with the potential to adversely impact organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, or the Nation through an information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service.
NIST SP 800-611 senseview framework →
§1
The potential source of an adverse event.
Wordset Dictionary4 sensesview framework →
§1
declaration of an intention or a determination to inflict harm on another
§2
a warning that something unpleasant is imminent
§3
a person who inspires fear or dread
§4
something that is a source of danger
NIST SP 800-172r31 senseview framework →
§1 · glossary
Any circumstance or event with the potential to adversely impact organizational operations, organizational assets, individuals, other organizations, or the Nation through a system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service. [21]
Attribution from the CKI glossary mapping stage (glossary)
NIST SP 800-171r31 senseview framework →
§1 · glossary
Any circumstance or event with the potential to adversely impact organizational operations, organizational assets, individuals, other organizations, or the Nation through a system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service. [55]
Attribution from the CKI glossary mapping stage (glossary)
TSP Section 1001 senseview framework →
§1 · glossary
Any circumstance or event, arising from human actions or natural events, that could potentially impair ( a ) the achievement of an entity's objectives, its assets, or activities of its personnel, or ( b ) other entities through unauthorized access, destruction, disclosure, modification of data, or denial of service.
Attribution from the CKI glossary mapping stage (glossary)
Legacy lexicon import1 senseview framework →
§1 · legacy_primary
Any circumstance or event with the potential to adversely impact organizational operations (including mission, functions, image, or reputation), organizational assets, or individuals through an information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service. Also, the potential for a threat-source to successfully exploit a particular information system vulnerability.
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

related