Certified Information Security Manager (CISM)Information Security Risk ManagementMedium
An organization is developing a new critical business application. The information security manager wants to proactively identify and categorize potential threats to the application during its design phase to ensure appropriate security controls are embedded early. Which threat modeling methodology would be MOST effective for systematically identifying and categorizing threats based on common attack types?
- AVulnerability scanning.
- BFIPS 199.
- CPenetration testing.
- DSTRIDE.
Show answer & explanationAnswer & explanation
Correct answer: D. STRIDE.
STRIDE is a well-known threat modeling methodology that categorizes threats into six distinct types: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. It is highly effective for systematically identifying threats during the design phase of an application.
Why the other options are wrong
- A. Vulnerability scanning identifies weaknesses in implemented systems, not potential threats during the design phase.
- B. FIPS 199 is a standard for categorizing information and information systems by impact, not a threat modeling methodology.
- C. Penetration testing is a post-development activity to find exploitable vulnerabilities in a running system.
STRIDE Threat Modeling
A threat modeling methodology used to identify and categorize threats to a system based on six common categories: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.
- Applied during the design phase.
- Systematically identifies diverse threat types.
- Helps ensure comprehensive security control design.
Memory trick: STRIDE: Steps to identify threats in the design.