Threat

From FISMApedia
Jump to: navigation, search

CNSSI 4009

Any circumstance or event with the potential to adversely impact an IS through unauthorized access, destruction, disclosure, modification of data, and/or denial of service.

FIPS 200

Any circumstance or event with the potential to adversely impact organizational operations (including mission, functions, image, or reputation), organizational assets, or individuals through an information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service. Also, the potential for a threat-source to successfully exploit a particular information system vulnerability. (CNSS Instruction 4009 Adapted)

NIST SP 800-16

An activity, deliberate or unintentional, with the potential for causing harm to an automated information system or activity.

NIST SP 800-18r1

Any circumstance or event with the potential to adversely impact agency operations (including mission, functions, image, or reputation), agency assets, or individuals through an information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service. (CNSS Inst. 4009, Adapted)

NIST SP 800-26

Threat is an event or activity, deliberate or unintentional, with the potential for causing harm to an IT system or activity.

NIST SP 800-27rA

Any circumstance or event with the potential to harm an information system through unauthorized access, destruction, disclosure, modification of data, and/or denial of service. Threats arise from human actions and natural events.

NIST SP 800-28v2

A possible danger to a computer system, which may result in the interception, alteration, obstruction, or destruction of computational resources, or other disruption to the system.

NIST SP 800-30

The potential for a threat-source to exercise (accidentally trigger or intentionally exploit) a specific vulnerability.

NIST SP 800-32

Any circumstance or event with the potential to cause harm to an information system in the form of destruction, disclosure, adverse modification of data, and/or denial of service. (NS4009)

NIST SP 800-33

The potential for a "threat source" (defined below) to exploit (intentional) or trigger (accidental) a specific vulnerability.

NIST SP 800-37

Any circumstance or event with the potential to adversely impact agency operations (including mission, functions, image, or reputation), agency assets, or individuals through an information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service. (CNSS Inst. 4009, Adapted)

NIST SP 800-40

Any circumstance or event, deliberate or unintentional, with the potential for causing harm to a system.

NIST SP 800-47

The potential for a threat-source to exercise (accidentally trigger or intentionally exploit) a specific vulnerability.

NIST SP 800-53AdF

Any circumstance or event with the potential to adversely impact agency operations (including mission, functions, image, or reputation), agency assets, or individuals through an information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service. [CNSS Inst. 4009, Adapted]

NIST SP 800-53r1

Any circumstance or event with the potential to adversely impact agency operations (including mission, functions, image, or reputation), agency assets, or individuals through an information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service.

NIST SP 800-53r2

Any circumstance or event with the potential to adversely impact agency operations (including mission, functions, image, or reputation), agency assets, or individuals through an information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service. (CNSS Inst. 4009, Adapted)

NIST SP 800-57P2

Any circumstance or event with the potential to adversely impact agency operations (including mission function, image, or reputation), agency assets or individuals through an information system via unauthorized access, destruction, disclosure, modification of data, and/or denial of service (SP800-53).

NIST SP 800-61

The potential source of an adverse event.

NIST SP 800-61r1

The potential source of an adverse event.

NIST SP 800-66

The potential for a threat source to exercise (accidentally trigger or intentionally exploit) a specific vulnerability. (NIST SP 800-30)