Threat Modelling Flashcards

(4 cards)

1
Q

What is threat modelling?

A

A technique to analyse a system’s security and privacy concerns.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the five key phases of threat modelling?

A

Asset identification - determine what you’re protecting.
Threat analysis - identify potential attacks or events that could compromise these assets.
Vulnerability analysis - pinpoint weakness both technical and organisational.
Risk assessment - evaluate the likelihood and impact of each event.
Risk communication - share findings with key stakeholders.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the STRIDE threat model?

A

Spoofing
Tampering
Repudiation
Information disclosure
Denial of service
Elevation of privilege

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the DREAD threat model?

A

Damage potential
Reproducibility
Exploitability
Affected users
Discoverability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly