In a world where there are limited resources for implementing and maintaining controls, we need some mechanism to determine where to spend our time and effort. Fortunately for us, smart people have already thought about, and come up with, a way to do just that: the Risk/Threat Assessment.