Quiz Entry - updated: 2026.07.30
How are threats to information commonly categorised by their origin?
Split them first into accidental vs. deliberate, then by source: people, organisation, technology, and force majeure.
* Threats split by origin into accidental (= Safety) and deliberate (= Security), each with its typical sources. *
Accidental / non-deliberate (zufällig):
- Force majeure (höhere Gewalt): storms, fire, water, earthquake, war
- Technical failure: bad maintenance, misconfiguration, buggy software/firmware, undersized systems
- Human error: negligence, indifference, ignorance, gullibility (Fahrlässigkeit, Unwissenheit, Leichtgläubigkeit)
- Organisational weakness: unclear responsibilities, missing processes/strategy, poor awareness, no controls
Deliberate / intentional (vorsätzlich):
- Malware (viruses, worms, trojans), data theft, extortion, espionage, cyberwar, misuse of IT
Why the split matters: it maps directly onto Safety vs. Security — accidental threats are the realm of safety, deliberate ones the realm of security (an adaptive attacker who works around your defences).
Go deeper:
Threat (computer security) (Wikipedia) — classifies threats by origin — deliberate vs accidental vs environmental — matching this card's split.
IT-Grundschutz elementary threats (Wikipedia) — the German BSI catalog (force majeure, technical failure, human error, organisational shortcomings, deliberate acts) that is the direct source of this categorisation.
IEEE Spectrum — The Real Story of Stuxnet — a landmark deliberate attack: how Stuxnet sabotaged Iran's centrifuges via Siemens industrial controllers.