Identified threats are analysed and prioritised and are addressed accordingly
Context and Guidance: Threats must be evaluated to determine which warrant the most and the timeliest attention based on their likely intent, capability, target, and potential to adversely impact the function as described in the threat profile. Threats should be addressed in order of priority to facilitate an effective response. Actions taken may be to analyse the threat to further understand potential impact, implement controls to mitigate the risk associated with the threat, or to adjust monitoring activities to look for indicators of the threat.
Related Practices • Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: THREAT-2d, THREAT-2g, THREAT-2j.