Threat Source
A threat source is any person, group, system, condition, or event that could cause harm to an organization's information or assets. It may act deliberately, such as an attacker exploiting a weakness, or accidentally, such as a situation that unintentionally triggers a vulnerability. Identifying threat sources is a foundational step in understanding what an organization needs to defend against.
A threat source is the intent and method targeted at the intentional exploitation of a vulnerability, or a situation and method that may accidentally trigger a vulnerability. It encompasses categories of people, objects, conditions, systems, or events that represent potential sources of harm to information assets, including intentional adversaries and accidental or environmental causes. In NIST usage, the terms 'threat source' and 'threat agent' are treated as synonymous rather than hierarchical; practitioners should be aware that some non-authoritative sources incorrectly describe a threat agent as a subcomponent of the threat source. Insider threats (individuals with authorized access or organizational knowledge who may cause harm) are one recognized class of threat source. Threat source identification is typically an input to risk assessment activities, informing how likely and impactful a given threat scenario may be, though it does not by itself quantify risk.
Why it matters
Identifying threat sources is foundational to any credible risk assessment because an organization cannot meaningfully prioritize defenses against threats it has not first named. A threat source frames the question of who or what could cause harm, whether a deliberate adversary exploiting a vulnerability or an accidental condition or event that unintentionally triggers one. Without this step, risk decisions tend to be reactive and tool-driven rather than grounded in an understanding of what the organization actually needs to defend against.
A common expert correction is the treatment of the relationship between 'threat source' and 'threat agent.' Some non-authoritative sources describe a threat agent as a subcomponent of a threat source, but in NIST usage the two terms are treated as synonymous rather than hierarchical. Practitioners relying on the hierarchical interpretation may build risk models that do not align with authoritative definitions, which can create confusion when mapping to frameworks or communicating with auditors and stakeholders.
Threat sources also include categories that are easy to overlook, such as insider threats. CISA defines insider threat as the potential for an insider to use their authorized access or understanding of an organization to harm that organization. Because insiders operate with legitimate access, they represent a recognized class of threat source that purely perimeter-focused defenses may fail to address, reinforcing why threat source identification must be deliberate and comprehensive rather than assumed.
Who it's relevant to
Inside Threat Source
Common questions
Answers to the questions practitioners most commonly ask about Threat Source.