{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"cyber_security","domain":["Risk Assessment & Management","Logging, Monitoring & Detection"],"inherent_rating":"high","taxonomy":["nist-800-30-threat-source"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Acyber-adversary-threat-sources","description":"Because capable, motivated threat actors - outsiders, privileged and non-privileged insiders, organized groups, competitors, malicious partners or suppliers, and nation-states - actively target the organization's cyber resources, deliberate attacks are attempted against its systems and data, resulting in compromise, disruption, or theft when defenses are outmatched.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"high","risk_id":"cyber-adversary-threat-sources","taxonomies":["nist-800-30-threat-source"],"treatment":"mitigate"},"id":"risk:cyber-adversary-threat-sources","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Acyber-adversary-threat-sources","sourceIds":["aiuc-1","cobit-2019","coso-ic","gdpr","iso-27001","iso-31000","nist-800-53","nist-csf-2","nydfs-500","soc1","soc2","sox"],"sourceUrl":null,"title":"Attacks by capable, motivated threat actors","type":"risk"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2197453a5f72d08e056274c107712e69d0bc55d818d6145e05c90a85813b2be6","properties":{"rationale":"Declaring incidents when criteria are met triggers the response that contains and limits attack impact.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-log-06-735bbc3e.json","sourceId":"uc:UC-LOG-06","targetDetailPath":"/data/v1/records/risk-cyber-adversary-threat-sources-fa9e3003.json","targetId":"risk:cyber-adversary-threat-sources","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3c2c2d06f4f2cac0c9f4d36baee8ef688aedb5a600f946e929e640d4a494520a","properties":{"rationale":"Monitoring provider security-relevant events detects the malicious or compromised supplier threat vector.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-log-09-54136146.json","sourceId":"uc:UC-LOG-09","targetDetailPath":"/data/v1/records/risk-cyber-adversary-threat-sources-fa9e3003.json","targetId":"risk:cyber-adversary-threat-sources","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:52fddd6bb4310a990e0736070615bf075c1bea5afacc03c4d9e545908a07e89a","properties":{"rationale":"GV.RM-03 member folds cyber risk into ERM, giving threats enterprise governance and resourcing, an enabler rather than the operative defense against attackers.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-02-0f8519bb.json","sourceId":"uc:UC-RISK-02","targetDetailPath":"/data/v1/records/risk-cyber-adversary-threat-sources-fa9e3003.json","targetId":"risk:cyber-adversary-threat-sources","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:56b287868d8de8b35f4d342ac4ffa8734ee89f732abced69770e766a0f24580a","properties":{"rationale":"Impact/criticality categorization prioritizes protective and resilience investment on high-value systems: necessary context, not the operative defense (inventory-type enabler).","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-18-23752e70.json","sourceId":"uc:UC-RISK-18","targetDetailPath":"/data/v1/records/risk-cyber-adversary-threat-sources-fa9e3003.json","targetId":"risk:cyber-adversary-threat-sources","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5ffb88ce652506ecf84fb88b264d0eb42d61ca1f72fd14d38745d836f4be9592","properties":{"rationale":"NYDFS 500.9 member and explicit cyber scope make the assessment periodically surface evolving cyber threats for treatment, enabling context not the operative defense.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-06-e9599494.json","sourceId":"uc:UC-RISK-06","targetDetailPath":"/data/v1/records/risk-cyber-adversary-threat-sources-fa9e3003.json","targetId":"risk:cyber-adversary-threat-sources","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a7a312b7d87fca167236f898d8c437bbdcc1439402e4fc4bbe3b85a9582e1f32","properties":{"rationale":"Operating malware defense and network/endpoint security is a first-order preventive defense that stops attacks from succeeding.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-13-aa7feb8e.json","sourceId":"uc:UC-BCDR-13","targetDetailPath":"/data/v1/records/risk-cyber-adversary-threat-sources-fa9e3003.json","targetId":"risk:cyber-adversary-threat-sources","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bbe0ad5da2b39a58b8954b219d172888ed0425e4df42439924f053d8affb1377","properties":{"rationale":"Continuous host/network/app monitoring to detect attacks and indicators of compromise is a first-order detective defense against active threat actors.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-log-04-4bc40d21.json","sourceId":"uc:UC-LOG-04","targetDetailPath":"/data/v1/records/risk-cyber-adversary-threat-sources-fa9e3003.json","targetId":"risk:cyber-adversary-threat-sources","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d7876743f7536fb475c57e9f619ed2f343ecbca56bbeb8b85a739fd03259944a","properties":{"rationale":"Camera surveillance and badge/entry logs detect physical intrusion attempts by threat actors.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-log-10-17ea2aa0.json","sourceId":"uc:UC-LOG-10","targetDetailPath":"/data/v1/records/risk-cyber-adversary-threat-sources-fa9e3003.json","targetId":"risk:cyber-adversary-threat-sources","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d992594f5cca715ae32ca0517b346d2c49e88b3e77dd1b1642d63829bde8e660","properties":{"rationale":"Assessing and expiring exceptions to security requirements reduces lingering security gaps that attackers exploit, shrinking attack surface.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-10-bbda2a79.json","sourceId":"uc:UC-ASSET-10","targetDetailPath":"/data/v1/records/risk-cyber-adversary-threat-sources-fa9e3003.json","targetId":"risk:cyber-adversary-threat-sources","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dec5b00cdde31ce06893dd667e3c0484986998830d51ec0ae7f72dca2ea50ec7","properties":{"rationale":"Threat intelligence and proactive threat hunting for IOCs directly detect and counter attacks by motivated threat actors, including activity that evades existing detection.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-17-4ea73b39.json","sourceId":"uc:UC-RISK-17","targetDetailPath":"/data/v1/records/risk-cyber-adversary-threat-sources-fa9e3003.json","targetId":"risk:cyber-adversary-threat-sources","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f58e9acd1374bdbce84d3819c1f1ddf398cf90c365abed4378c3b5e88b182afd","properties":{"rationale":"Security-event monitoring with alert triage contributes to detecting attacks, though specialized detection sits in dedicated SIEM/IDS controls.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-18-8ffbd456.json","sourceId":"uc:UC-ACCESS-18","targetDetailPath":"/data/v1/records/risk-cyber-adversary-threat-sources-fa9e3003.json","targetId":"risk:cyber-adversary-threat-sources","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f98770c87f438334b14b65b4fe3ee1b7ef1495a80f1115a811ae654d21e427c5","properties":{"rationale":"SIEM correlation and threat-intel enrichment detect attacks by matching observed activity to known adversary indicators.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-log-05-8f316c34.json","sourceId":"uc:UC-LOG-05","targetDetailPath":"/data/v1/records/risk-cyber-adversary-threat-sources-fa9e3003.json","targetId":"risk:cyber-adversary-threat-sources","type":"mitigates"}],"schemaVersion":1}
