Module 3.2 Flashcards
What are the factors of Treat Modeling
Threat actors, Threat source/agent, Threat event
3 Threat Actors (Understanding the operational environment)
Motivation, Capabilities, Persistence
Categories of Threat Agents
Accidental, Structural, Environmental
Actors in Accidental Threat Agent
User, Privileged user or administrator
Components of Structural Threat Agent
IT equipment, Environmental controls, Software
Examples of Environmental Threat Agent
Natural or man-made disaster, Unusual/rare natural events, Infrastructure failure (Telecommunications, Power)
STRIDE model acronym
Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Escalation of Privilege
DREAD Acronym (Rating Thread Impact)
Damage, Reproducibility, Exploitability, Affected Users, Discoverability
Set of points on the boundary of a system, system element, or environment where an attacker can try to enter, cause an effect on, or extract data from
Attack Surface
Relative Attack Surface Quotient (RASQ)
How to define Attack Surface (C.P.M.T.L)
Creative, Persistent, Methodical, Technical, Log Analysis
How to Validate Attack Surface
Penetration testing, Security Information and Event Management (SEIM) systems
Threat Modeling Methodologies (Standards)
ISO/IEC 27005
ISO/IEC 31000
NIST SP 800-30 r1
HTRA