Threat Modelling Flashcards
(4 cards)
What is threat modelling?
A technique to analyse a system’s security and privacy concerns.
What are the five key phases of threat modelling?
Asset identification - determine what you’re protecting.
Threat analysis - identify potential attacks or events that could compromise these assets.
Vulnerability analysis - pinpoint weakness both technical and organisational.
Risk assessment - evaluate the likelihood and impact of each event.
Risk communication - share findings with key stakeholders.
What is the STRIDE threat model?
Spoofing
Tampering
Repudiation
Information disclosure
Denial of service
Elevation of privilege
What is the DREAD threat model?
Damage potential
Reproducibility
Exploitability
Affected users
Discoverability