Threat
A threat is any circumstance or event that has the potential to cause harm to an organization's operations, assets, or people. In a security context, threats can come from outside attackers or from insiders who misuse their authorized access. A threat represents the possibility of harm, which is distinct from an actual incident or breach having occurred.
In information security risk management, a threat is any circumstance or event with the potential to adversely impact organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, or other organizations. Threats may be external or internal; an insider threat, for example, is the potential for an insider to use their authorized access or understanding of an organization to cause harm. Threats are typically assessed against vulnerabilities and potential impact during risk assessment activities, which inform control selection and treatment decisions. Managing threats involves detecting cyber threats, preventing attacks, and responding to security events. A threat denotes the potential for harm rather than a realized event, and identifying a threat does not by itself indicate that a control has failed or that an incident has occurred.
Why it matters
Understanding threats is foundational to both SOC 2 examinations and ISO 27001 certification because risk-based control selection begins with identifying what could cause harm. A threat represents the potential for adverse impact to organizational operations, assets, individuals, or other organizations, and distinguishing this potential from a realized incident is critical. Identifying a threat does not by itself mean a control has failed or that a breach has occurred; it simply informs the organization about where harm could originate so that vulnerabilities and potential impact can be assessed.
In most engagements, threats drive the risk assessment activities that shape which controls an organization implements and how those controls are tested. Under ISO 27001, the ISMS requirements in clauses 4 through 10 call for risk assessment, and the results inform which Annex A reference controls are selected through the Statement of Applicability. Under SOC 2, the Security category (the Common Criteria) addresses risk identification and management as part of the criteria a CPA firm evaluates. In both cases, a clear understanding of the threat landscape helps ensure that control selection is defensible and proportionate rather than arbitrary.
Threats can originate externally from attackers or internally from insiders who misuse their authorized access or understanding of the organization to cause harm. Because threats represent possibilities rather than certainties, managing them is an ongoing process of detection, prevention, and response rather than a one-time exercise. Neither a SOC 2 report nor an ISO 27001 certificate guarantees freedom from threats being realized; each attests only to the controls and scope covered, depending on the engagement.
Who it's relevant to
Inside Threat
Common questions
Answers to the questions practitioners most commonly ask about Threat.