Threats to Information Systems
On this page
3.2 Threats to Information Systems
Suggested retrieval lesson: 20–30 minutes.
Recall first
- Distinguish threat, vulnerability, and risk.
- Is phishing a threat, vulnerability, or risk?
- Give one non-malicious and one environmental threat.
Answer cold first.
The essential distinction
- A threat is a circumstance or event with the potential to adversely affect an asset or organization. It may be deliberate, accidental, environmental, or structural.
- A vulnerability is a weakness that a threat can exploit, such as an unpatched server, excessive privilege, weak password, or untrained user.
- Risk is the possibility of adverse impact arising when a threat exploits a vulnerability. A simple exam model is
risk ≈ likelihood × impact; real NIST risk assessment is more nuanced and considers uncertainty, threat, vulnerability, and consequences. NIST SP 800-30 Rev. 1
A threat actor is the person, group, process, or natural force causing or capable of causing harm. An attack is an actual attempt to exploit a weakness. Thus, phishing is an attack technique/threat event; an untrained recipient is a vulnerability; likely payroll fraud is the risk.
Common threat classes
- Malware: malicious software such as viruses, worms, trojans, spyware, and ransomware. Ransomware commonly affects availability and may also steal data.
- Social engineering: manipulating people to reveal secrets or perform unsafe actions—phishing, pretexting, baiting, and impersonation.
- Credential and access attacks: password guessing, credential stuffing, stolen tokens, and privilege abuse.
- Application/network attacks: exploiting injection, misconfiguration, vulnerable services, denial-of-service, or interception.
- Insider and human error: careless disclosure, accidental deletion, malicious insider action, or incorrect configuration. Not all incidents are external hacking.
- Physical and environmental: theft, fire, flood, power failure, overheating, and hardware failure.
- Supply-chain and third-party: compromised vendors, libraries, service providers, or updates.
Think in an attack chain: asset and business process → threat actor/event → vulnerability → exploit → impact. Controls can break any link.
Worked example: university exam portal
Asset: exam questions and student records. Threat: an attacker sends a convincing password-reset message. Vulnerability: users lack phishing training and MFA is absent. Attack: a user submits credentials; the attacker logs in. Risk: question leakage or record alteration, with confidentiality and integrity impacts. Controls include MFA (reduces credential usefulness), user reporting/training, rate limits, monitoring for unusual login, and tested recovery. The risk assessment should rank this against a flood or accidental deletion by likelihood and impact, not merely list scary threats.
Exercise — reveal after committing
“An online store has an unpatched payment server. Criminals may exploit it, causing card-data theft with a severe regulatory and customer impact.” Label the threat, vulnerability, and risk.
Revealed answer: Threat: criminals/exploitation event. Vulnerability: unpatched payment server. Risk: the likelihood and severe impact of card-data theft and its consequences. The sentence contains both a threat actor and a threat event; clearly labeling both earns precision.
Exam lens
- Never use threat, vulnerability, and risk as synonyms.
- “Risk = threat × vulnerability” is a useful memory aid but incomplete; state likelihood and impact for a better answer.
- Include accidental, insider, physical, and third-party threats—not only hackers and viruses.
- Name the asset and impact; a threat matters because of what it can damage.
Rapid revision checklist
- Define threat, threat actor, vulnerability, attack, and risk.
- Apply likelihood × impact cautiously as an exam model.
- Classify malware, social engineering, insider, physical, and supply-chain examples.
- Trace asset → threat → vulnerability → exploit → impact.
- Explain why one threat can affect confidentiality, integrity, and availability differently.
Key takeaways
- Threat is potential harm; vulnerability is exploitable weakness; risk combines likelihood and impact.
- Security assessment must include people, process, technology, suppliers, and the physical environment.
- Identify assets and impacts before prioritizing controls.
- A layered control strategy breaks the attack chain at several points.
Sources
- Rainer & Prince, Management Information Systems (Wiley) — textbook exam framing for IS threats and security.
- Laudon & Laudon, Management Information Systems: Managing the Digital Firm, 10th ed. — textbook exam framing for vulnerabilities, threats, and controls.
- Boddy & Boonstra, Managing Information Systems: Strategy and Organization — textbook exam framing.
- NIST, SP 800-30 Rev. 1: Guide for Conducting Risk Assessments — supplement for risk terminology and assessment.
- NIST, Cybersecurity Framework 2.0 — supplement for organizing risk-management outcomes.