FFIEC Cybersecurity Assessment Tool (CAT)
Inherent Risk Profile: Risk Categories

FFIEC Cybersecurity Assessment Tool (CAT) CAT-IRP-5: External threats

Analyzes attack frequency, types of threats, and the threat landscape facing the institution

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 19 controls across 14 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-DE.AE-07 Cyber threat intelligence and other contextual information are integrated into the analysis
  • NIST-CSF-ID.RA-02 Cyber threat intelligence is received from information sharing forums and sources

BSI IT-Grundschutz · 1 control

  • BSI-16 Threat intelligence integration

FISMA · 1 control

ISO/IEC 27011:2024 · 1 control

ISO/IEC 27400:2022 · 1 control

  • 27400-5.1 IoT Security and Privacy Governance
  • NATO-NCIRC-4 Cyber Threat Intelligence Sharing and Coordinated Vulnerability Disclosure
  • ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture
  • DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Inherent Risk Profile: Risk Categories

Query this from an agent

The graph holds this control, the 19 it maps to, and the evidence behind each claim, over MCP and REST.