Certified Information Security Manager (CISM)Information Security Risk ManagementHard

An organization is conducting a risk assessment for a new critical business application. The information security manager is evaluating various threat actors and their potential capabilities. Which of the following threat modeling approaches would BEST help in proactively identifying and prioritizing potential threats from these actors against the application?

  1. AFAIR
  2. BNIST RMF
  3. CSTRIDE
  4. DOCTAVE
Show answer & explanation

Correct answer: C. STRIDE

STRIDE (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege) is a widely used threat modeling methodology that helps identify and categorize potential threats against an application, especially useful during the design phase to proactively build in security.

Why the other options are wrong

  • A. FAIR (Factor Analysis of Information Risk) is a quantitative risk assessment methodology focused on financial impact, not a threat modeling approach for identifying threat types.
  • B. NIST RMF (Risk Management Framework) is a comprehensive framework for managing organizational risk, not a specific threat modeling approach for applications.
  • D. OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation) is a risk-based assessment methodology focused on organizational risk, not specifically on application-level threat categorization.

STRIDE Threat Modeling

A systematic threat modeling methodology used to identify and classify threats to applications and systems based on six categories: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.

  • Used early in the SDLC.
  • Categorizes threats for systematic analysis.
  • Helps design security controls proactively.

Memory trick: STRIDE for application threats.

More Information Security Risk Management questions