2.4 CYBERSECURITY CONCEPTS We shall now define the cybersecurity concepts that we use throughout the Guide. 2.4.1 CYBER THREATS The term cyber threat is part of the popular press lexicon. Whenever we use this phrase in this Guide, know that we mean a potential violation of security properties (ITU 2009f). We further differentiate threats by character, impact, origin and actor as follows: 2.4.1.1 Accidental or Intentional Threats Accidental threats occur without premeditated intent. For example, system or software malfunctions and physical failures. However, intentional threats result from deliberate acts against the security of an asset. Intentional threats range from casual examination of a computer network using easily available monitoring tools, to sophisticated attacks using special system knowledge. Intentional threats that materialise become attacks. 2.4.1.2 Active or Passive Threats Active threats are ones that result in some change to the state or operation of a system, such as the modification of data and the destruction of physical equipment. Conversely, passive threats do not involve a change of state to the equipment. Passive threats aim to glean information from a system without affecting the resources of the system. Common passive threat techniques include eavesdropping, wiretapping and deep packet analysis or inspections. Successful passive threats become passive attacks. 2.4.1.3 Threat Source We regard a threat source as an entity that desires to breach information or physical assets’ security controls. The threat source ultimately aims to benefit from the breach for example financially. We identify what we regard as the main threat sources in Figure 2. 15

Select target paragraph3