LECTURE 3: UNDERSTAND AND APPLY THREAT MODELING CONCEPTS AND METHODOLOGIES

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/16

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 5:00 PM on 10/6/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

17 Terms

1
New cards

Threat modeling is a security process used to:

  • Identify possible threats.

  • Analyze how those threats could exploit vulnerabilities

  • Find out how valuable assets could be harmed.

  • Choose security controls to protect them.

Its goal is to prevent security problems before attacks happen.

2
New cards

ASSET

An asset is any element that has a value for organization.

A resource, process, product, computing infrastructure, and so forth that an organization has determined must be protected.

3
New cards

THREAT

The presence of any potential event that causes an unwanted impact on the organization

4
New cards

ATTACK

The presence of any actual event that causes an unwanted impact on the organization.

5
New cards

VULNERABILITY

The absence of safeguard OR a system weakness might be used by threat to cause a damage to the system.

6
New cards

THREAT AGENT

The entity ( a person or process) initiates the threat.

7
New cards

EXPLOIT

if the vulnerability found by threat agent and threat initiated.

8
New cards

Threats: Potential events that may cause harm. These are the types of Threats

  • Cyber attacks

  • Malware

  • Phishing

  • DoS

  • Supply chain attacks


9
New cards

Vulnerabilities: Weaknesses that can be exploited.

  • People: Lack of awareness, weak authentication.

  • Process: Poor policies, misconfiguration.

  • Technology: Software bugs, unpatched systems


10
New cards

Assets: Anything of value to the organization.

  • Data

  • Systems

  • Services

  • Infrastructure

  • Reputation

Remember: Threats exploit vulnerabilities and impact assets.

11
New cards

CONTROL / COUNTERMEASURE / SAFEGUARD

  • Any step/action to prevent the threat exploiting the vulnerability.

  • (OR): Minimize the damage of the exploit


12
New cards

RISK ELEMENTS

A risk is the possibility or likelihood that a threat will exploit a vulnerability resulting in a loss such as harm to an asset.

13
New cards

Risk management

Risk management uses controls to reduce vulnerabilities and minimize threat impacts.

Risk elements are:

  • Threat

  • Vulnerability

  • Asset

  • Damage


14
New cards

Threat modeling can be performed as:

Proactively

  • During system design and development

  • So, Security is built in from the start


Reactively

  • After deployment or after incidents

  • Based on observed attacks or failures


15
New cards

Proactive (Defensive) Approach:

Planning for security before building. You predict potential attacks and build defenses right into the system while designing and coding it. Security is built-in from day one.

16
New cards

Reactive (Adversarial) Approach:

Fixing security after building. You add defenses or patches only after the product is already live or after an attack has occurred.

17
New cards

Which approach is the preferred one:

Proactive threat modeling is the preferred and more effective approach.