2.4
CYBERSECURITY CONCEPTS
We shall now define the cybersecurity concepts that we use throughout the Guide.
2.4.1
CYBER THREATS
The term cyber threat is part of the popular press lexicon. Whenever we use this phrase
in this Guide, know that we mean a potential violation of security properties (ITU 2009f).
We further differentiate threats by character, impact, origin and actor as follows:
2.4.1.1
Accidental or Intentional Threats
Accidental threats occur without premeditated intent. For example, system or software
malfunctions and physical failures. However, intentional threats result from deliberate
acts against the security of an asset. Intentional threats range from casual examination
of a computer network using easily available monitoring tools, to sophisticated attacks
using special system knowledge. Intentional threats that materialise become attacks.
2.4.1.2
Active or Passive Threats
Active threats are ones that result in some change to the state or operation of a system,
such as the modification of data and the destruction of physical equipment. Conversely,
passive threats do not involve a change of state to the equipment. Passive threats aim to
glean information from a system without affecting the resources of the system. Common
passive threat techniques include eavesdropping, wiretapping and deep packet analysis
or inspections. Successful passive threats become passive attacks.
2.4.1.3
Threat Source
We regard a threat source as an entity that desires to breach information or physical
assets’ security controls. The threat source ultimately aims to benefit from the breach for
example financially. We identify what we regard as the main threat sources in Figure 2.
15