Topic summary
Threat (computer security)

Potential negative action or event facilitated by a vulnerability In computer security, a threat is an action or event that would result in an unwanted or negative impact to a computer system, software, data, or other IT resources. Many cyber threats are enabled by vulnerabilities. A threat can be either a negative "intentional" event like hacking or an "accidental" negative event or otherwise a circumstance, capability, action, or event (incident is often used as a blanket term). A threat actor who is an individual or group that can perform the threat action, such as exploiting a vulnerability to actualise a negative impact. An exploit is a vulnerability that a threat actor used to cause an incident. Phenomenology A basic model of system threats The term "threat" relates to some other basic security terms as shown in the following diagram: A resource (both physical or logical) can have one or more vulnerabilities that can be exploited by a threat agent in a threat action. The result can potentially compromise the confidentiality, integrity or availability properties of resources (potentially different than the vulnerable one) of the organization and others involved parties (custom