Difference between revisions of "Threat Action"

From Open Risk Manual
 
Line 5: Line 5:
  
 
=== VERIS Taxonomy of Threat Actions ===
 
=== VERIS Taxonomy of Threat Actions ===
The VERIS taxonomy<ref>http://veriscommunity.net/actions.html</ref> recognizes 7 distinct actions:
+
The VERIS taxonomy<ref>https://verisframework.org/actions.html</ref> recognizes 7 distinct actions:
 
* [[Malware]]
 
* [[Malware]]
 
* [[Hacking]]
 
* [[Hacking]]

Latest revision as of 13:33, 6 September 2023

Definition

Threat Action in the context of IT Security Risk is the specific set of activities used by a Threat Actor to create a Cyber Incident

Threat actions describe what the threat actor(s) did to cause or contribute to the incident. Every incident has at least one, but most will comprise multiple actions (and often across multiple categories).

VERIS Taxonomy of Threat Actions

The VERIS taxonomy[1] recognizes 7 distinct actions:

References