CRISC Certified in Risk and Information Systems ControlIT Risk AssessmentMedium
A financial institution is conducting an IT risk assessment for its new mobile banking application. The risk management team wants to understand the potential for fraudulent transactions originating from compromised user devices. Which of the following risk identification techniques would be MOST effective in systematically analyzing potential attack paths and vulnerabilities unique to the application's design and user interaction flows?
- ABrainstorming sessions with business stakeholders
- BThreat modeling
- CCompliance checklist assessments
- DReview of historical incident data
Show answer & explanationAnswer & explanation
Correct answer: B. Threat modeling
Threat modeling is a structured approach to identify potential threats, vulnerabilities, and attack vectors within a system or application. It is particularly effective for new applications like a mobile banking platform, as it systematically analyzes design and interaction flows to uncover unique risks.
Why the other options are wrong
- A. Brainstorming is useful for general risk identification but may not systematically uncover technical attack paths specific to application design.
- C. Compliance checklists verify adherence to regulations but do not typically analyze application design for specific attack paths or vulnerabilities.
- D. Historical incident data provides insight into past events but may not cover novel threats or vulnerabilities in a new application's unique design.
Threat Modeling
A structured process to identify, categorize, and prioritize potential threats to a system or application, along with the vulnerabilities that could allow those threats to materialize.
- Focuses on 'what could go wrong' from an attacker's perspective.
- Often performed early in the development lifecycle.
- Helps design security controls proactively.
Memory trick: Identify the 'threat' to your 'model' system early.