A risk model which explicitly represents the threats and classes of harm considered by those concerned with cyber resiliency. (This accommodates other stakeholders, in addition to systems security engineers.) Note: A cyber resiliency risk model emphasizes (but is not limited to) the APT as a threat source, and emphasizes the effects on missions and organizations of malicious cyber activities, as well as harm to systems that include cyber resources.
Source(s):
NIST SP 800-160 Vol. 2
[Superseded]