Threat Catalogue
A threat catalogue is a structured list of common information security threats, including the events, sources, and actions that could potentially harm an organization's systems or data. Organizations typically use it as a reference when identifying and assessing the risks they face. In a healthcare compliance context, it can support the risk analysis process by helping teams consider a broad range of potential threats to protected health information.
A threat catalogue is a curated, generally topically organized repository of information security threats that describes and structures potential threat events, threat sources, and harmful actions or inactions relevant to information systems. Examples include NIST's Mobile Threat Catalogue (MTC), which catalogues threats to mobile information systems, and schema-based catalogues such as the OpenSSF Gemara ThreatCatalog, which defines a set of topically associated threats as a metadata object containing a list of threat entries. Threat catalogues are commonly used as inputs to risk assessment and threat modeling workflows and may be paired with vulnerability-oriented resources such as CISA's Known Exploited Vulnerabilities (KEV) Catalog for prioritization. Note that a threat catalogue is not itself a regulatory requirement or a HIPAA-defined term; while the HIPAA Security Rule requires a risk analysis addressing threats and vulnerabilities to ePHI, it does not mandate use of any specific catalogue, and organizations should verify current regulatory expectations and select catalogues appropriate to their environment.
Why it matters
The HIPAA Security Rule requires covered entities and business associates to conduct a risk analysis that accounts for reasonably anticipated threats and vulnerabilities to electronic protected health information (ePHI). A threat catalogue supports that process by giving teams a structured, pre-organized reference of common threat events, sources, and actions, so that a risk analysis is less likely to overlook categories of harm that might otherwise go unconsidered. Using a recognized catalogue as an input can bring consistency and thoroughness to what is often an ad hoc exercise.
It is important to understand the limits of this tool in a compliance context. A threat catalogue is not a HIPAA-defined term, and the Security Rule does not mandate the use of any particular catalogue. Adopting one, whether NIST's Mobile Threat Catalogue, a schema-based resource such as the OpenSSF Gemara ThreatCatalog, or an internally maintained list, does not by itself satisfy the risk analysis obligation or establish HIPAA compliance. The catalogue is a reference input; the organization still must perform and document an analysis appropriate to its own environment, systems, and data flows.
Because no single catalogue covers every environment, teams generally need to select or tailor catalogues to their actual systems. A mobile-focused catalogue, for example, addresses threats to mobile information systems but would not on its own cover threats to on-premises servers or paper-based workflows. Organizations should treat a threat catalogue as one component of a broader risk management program and verify their approach against current regulatory expectations, noting that state law, the HITECH Act, or other frameworks may impose additional requirements.
Who it's relevant to
Inside Threat Catalogue
Common questions
Answers to the questions practitioners most commonly ask about Threat Catalogue.