Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    K
    All infographics
    Threat Modeling · Part 1

    Underneath it all, four questions

    The four questions that structure an FDA-ready medical device threat model, and what each one has to produce.

    Infographic: the four threat modeling questions - what are we working on, what can go wrong, what are we going to do about it, and did we do a good enough job - each with the artifacts it produces.
    Four questions, and every answer traces back to a patient harm. If an answer cannot be traced to a harm, it does not belong in the threat model.

    What the graphic says

    The full text version, so the content is readable without the image.

    The four questions

    The structure behind an FDA-ready medical device threat model. Four questions, and every answer traces to a patient harm.

    01. What are we working on?
    Scope, the data flow diagram (DFD), entry points, and trust boundaries. The system as an attacker sees it, not as the architecture deck draws it.
    02. What can go wrong?
    STRIDE per element proves coverage. Three CIA attack trees add depth, each one rooted in a specific patient harm.
    03. What are we going to do about it?
    Eliminate, mitigate, accept, or transfer - then score. Never accept or transfer in silence; the rationale is part of the record.
    04. Did we do a good enough job?
    The QA gate. Completeness, traceability, and the link from every threat to a patient harm.

    The Four Questions, from the MITRE / MDIC Playbook for Threat Modeling Medical Devices.

    More in Threat Modeling

    Ready when you are

    Get FDA cleared without the cybersecurity headaches.

    30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ FDA submissions.