Threat Modeling · Part 2
Four questions, nine steps
The nine-step workflow that turns the four threat modeling questions into a threat table and a residual risk position.
What the graphic says
The full text version, so the content is readable without the image.
The nine-step workflow
How the threat model actually gets built. One left-to-right pass produces the Threat Table and hands residual risk to the risk assessment.
- Q1 - What are we working on?
- Step 1: scope from the model. Step 2: build the DFD (to DFD level 3). Step 3: identify trust boundaries and entry points.
- Q2 - What can go wrong?
- Step 4: apply STRIDE per element. Step 5: build attack trees for depth where a threat warrants it.
- Q3 - What are we going to do about it?
- Step 6: build the threat table with initial risk. Step 7: choose a control for each threat.
- Q4 - Did we do a good enough job?
- Step 8: test the control. Step 9: record residual risk and run the QA gate.
Keep reading
More in Threat Modeling
Ready when you are
Get FDA cleared without the cybersecurity headaches.
30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ FDA submissions.
