Home / Function (NIST CSF 2.0) / ID - Identify / RA - Risks AsstThreats
NIST CSF Sub-Category ID.AM.03
Understanding and managing threats is crucial, and normative documents provide the frameworks and guidance necessary to identify, categorize, and respond to them systematically. Standards like ISO/IEC 27005 and guidance from NIST SP 800-30 outline methodologies for threat analysis and risk evaluation, while regulators such as ENISA in Europe and CISA in the U.S. publish threat reports and advisories that inform organizations of emerging risks. Laws and regulations, including the EU NIS2 Directive, often require organizations to assess threat landscapes and implement mitigations. By aligning with these normative documents, organizations can proactively anticipate cyber threats, prioritize defenses, and maintain compliance with national and international security expectations.