Skip to content
    Home / Function (NIST CSF 2.0) / ID - Identify / RA - Risks Asst

    Threats

    NIST CSF Sub-Category ID.AM.03

    Understanding and managing threats is crucial, and normative documents provide the frameworks and guidance necessary to identify, categorize, and respond to them systematically. Standards like ISO/IEC 27005 and guidance from NIST SP 800-30 outline methodologies for threat analysis and risk evaluation, while regulators such as ENISA in Europe and CISA in the U.S. publish threat reports and advisories that inform organizations of emerging risks. Laws and regulations, including the EU NIS2 Directive, often require organizations to assess threat landscapes and implement mitigations. By aligning with these normative documents, organizations can proactively anticipate cyber threats, prioritize defenses, and maintain compliance with national and international security expectations.

    NIST IR 8374 Rev. 1 Ransomware Risk Management: A Cybersecurity Framework 2.0 Community Profile

    The “Ransomware Risk Management: A Cybersecurity Framework 2.0 Community Profile” is a NIST publication that provides organizations with a practical guide to managing ransomware risks using the updated NIST Cybersecurity… Read More »NIST IR 8374 Rev. 1 Ransomware Risk Management: A Cybersecurity Framework 2.0 Community Profile

    CSA Cloud Adversarial Vectors, Exploits, and Threats (CAVEaT™): An Emerging Threat Matrix for Industry Collaboration

    The Cloud Security Alliance’s (CSA) Cloud Adversarial Vectors, Exploits, and Threats (CAVEaT™) is an emerging, cloud-centric threat matrix designed to address the unique and rapidly evolving security risks in cloud… Read More »CSA Cloud Adversarial Vectors, Exploits, and Threats (CAVEaT™): An Emerging Threat Matrix for Industry Collaboration

    MITRE CAPEC – Common Attack Pattern Enumeration and Classification Version 3.9

    The MITRE Common Attack Pattern Enumeration and Classification (CAPEC) is a publicly available, comprehensive catalog that documents and categorizes common attack patterns used by adversaries to exploit software and systems.… Read More »MITRE CAPEC – Common Attack Pattern Enumeration and Classification Version 3.9