The model must identify likely threat agents (insiders, organised crime, nation state, hacktivist) and their capability and intent, calibrating test sophistication accordingly.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated