§ 3.2Module 3

Threats to Information Systems

On this page

3.2 Threats to Information Systems

Suggested retrieval lesson: 20–30 minutes.

Recall first

  1. Distinguish threat, vulnerability, and risk.
  2. Is phishing a threat, vulnerability, or risk?
  3. Give one non-malicious and one environmental threat.

Answer cold first.

The essential distinction

A threat actor is the person, group, process, or natural force causing or capable of causing harm. An attack is an actual attempt to exploit a weakness. Thus, phishing is an attack technique/threat event; an untrained recipient is a vulnerability; likely payroll fraud is the risk.

Common threat classes

  1. Malware: malicious software such as viruses, worms, trojans, spyware, and ransomware. Ransomware commonly affects availability and may also steal data.
  2. Social engineering: manipulating people to reveal secrets or perform unsafe actions—phishing, pretexting, baiting, and impersonation.
  3. Credential and access attacks: password guessing, credential stuffing, stolen tokens, and privilege abuse.
  4. Application/network attacks: exploiting injection, misconfiguration, vulnerable services, denial-of-service, or interception.
  5. Insider and human error: careless disclosure, accidental deletion, malicious insider action, or incorrect configuration. Not all incidents are external hacking.
  6. Physical and environmental: theft, fire, flood, power failure, overheating, and hardware failure.
  7. Supply-chain and third-party: compromised vendors, libraries, service providers, or updates.

Think in an attack chain: asset and business process → threat actor/event → vulnerability → exploit → impact. Controls can break any link.

Worked example: university exam portal

Asset: exam questions and student records. Threat: an attacker sends a convincing password-reset message. Vulnerability: users lack phishing training and MFA is absent. Attack: a user submits credentials; the attacker logs in. Risk: question leakage or record alteration, with confidentiality and integrity impacts. Controls include MFA (reduces credential usefulness), user reporting/training, rate limits, monitoring for unusual login, and tested recovery. The risk assessment should rank this against a flood or accidental deletion by likelihood and impact, not merely list scary threats.

Exercise — reveal after committing

“An online store has an unpatched payment server. Criminals may exploit it, causing card-data theft with a severe regulatory and customer impact.” Label the threat, vulnerability, and risk.

Revealed answer: Threat: criminals/exploitation event. Vulnerability: unpatched payment server. Risk: the likelihood and severe impact of card-data theft and its consequences. The sentence contains both a threat actor and a threat event; clearly labeling both earns precision.

Exam lens

Rapid revision checklist

Key takeaways

  1. Threat is potential harm; vulnerability is exploitable weakness; risk combines likelihood and impact.
  2. Security assessment must include people, process, technology, suppliers, and the physical environment.
  3. Identify assets and impacts before prioritizing controls.
  4. A layered control strategy breaks the attack chain at several points.

Sources