Certified Information Security Manager (CISM)Information Security Risk ManagementMedium

An organization is conducting a risk assessment for a new critical business application. The information security manager wants to systematically identify potential threats to the application by focusing on its design and functionality. Which of the following methodologies is BEST suited for this purpose?

  1. AReviewing past penetration test reports of similar applications.
  2. BVulnerability scanning using automated tools.
  3. CPerforming a Business Impact Analysis (BIA).
  4. DApplying the STRIDE threat modeling methodology.
Show answer & explanation

Correct answer: D. Applying the STRIDE threat modeling methodology.

The question asks to systematically identify threats by focusing on the application's 'design and functionality'. STRIDE is a threat modeling methodology specifically designed for this purpose. It categorizes threats based on spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege, directly addressing design-level vulnerabilities.

Why the other options are wrong

  • A. Past penetration test reports might offer insights but are historical and may not cover the unique design and functionality of the new application.
  • B. Vulnerability scanning identifies technical flaws in implemented code or infrastructure, not design-level threats.
  • C. A BIA identifies the impact of disruptions, not the threats to the application's design or functionality.

STRIDE Threat Modeling

A systematic threat modeling methodology used to identify threats to an application or system, categorized by Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.

  • Focuses on system design.
  • Identifies a broad range of threats.
  • Supports 'shift-left' security.

Memory trick: STRIDE helps you step through design threats.

More Information Security Risk Management questions