1/16
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Threat modeling is a security process used to:
Identify possible threats.
Analyze how those threats could exploit vulnerabilities
Find out how valuable assets could be harmed.
Choose security controls to protect them.
Its goal is to prevent security problems before attacks happen.
ASSET
An asset is any element that has a value for organization.
A resource, process, product, computing infrastructure, and so forth that an organization has determined must be protected.
THREAT
The presence of any potential event that causes an unwanted impact on the organization
ATTACK
The presence of any actual event that causes an unwanted impact on the organization.
VULNERABILITY
The absence of safeguard OR a system weakness might be used by threat to cause a damage to the system.
THREAT AGENT
The entity ( a person or process) initiates the threat.
EXPLOIT
if the vulnerability found by threat agent and threat initiated.
Threats: Potential events that may cause harm. These are the types of Threats
Cyber attacks
Malware
Phishing
DoS
Supply chain attacks
Vulnerabilities: Weaknesses that can be exploited.
People: Lack of awareness, weak authentication.
Process: Poor policies, misconfiguration.
Technology: Software bugs, unpatched systems
Assets: Anything of value to the organization.
Data
Systems
Services
Infrastructure
Reputation
Remember: Threats exploit vulnerabilities and impact assets.
CONTROL / COUNTERMEASURE / SAFEGUARD
Any step/action to prevent the threat exploiting the vulnerability.
(OR): Minimize the damage of the exploit
RISK ELEMENTS
A risk is the possibility or likelihood that a threat will exploit a vulnerability resulting in a loss such as harm to an asset.
Risk management
Risk management uses controls to reduce vulnerabilities and minimize threat impacts.
Risk elements are:
Threat
Vulnerability
Asset
Damage
Threat modeling can be performed as:
Proactively
During system design and development
So, Security is built in from the start
Reactively
After deployment or after incidents
Based on observed attacks or failures
Proactive (Defensive) Approach:
Planning for security before building. You predict potential attacks and build defenses right into the system while designing and coding it. Security is built-in from day one.
Reactive (Adversarial) Approach:
Fixing security after building. You add defenses or patches only after the product is already live or after an attack has occurred.
Which approach is the preferred one:
Proactive threat modeling is the preferred and more effective approach.