ISC2 CISSP (Certified Information Systems Security Professional)Security Assessment and TestingMedium

A security analyst is developing a threat modeling methodology for a new critical application. The analyst wants to systematically identify potential threats, vulnerabilities, and countermeasures from an attacker's perspective. Which of the following threat modeling frameworks is explicitly designed to identify threats against systems and applications by categorizing them into six main areas?

  1. ANIST CSF
  2. BMITRE ATT&CK
  3. CDREAD
  4. DSTRIDE
Show answer & explanation

Correct answer: D. STRIDE

STRIDE is a well-known threat modeling framework developed by Microsoft that categorizes threats into six areas: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. It is explicitly designed for identifying threats against systems and applications.

Why the other options are wrong

  • A. NIST CSF (Cybersecurity Framework) is a high-level framework for managing cybersecurity risk, not a specific methodology for identifying application threats.
  • B. MITRE ATT&CK maps adversary tactics and techniques, providing a knowledge base of real-world attacks, but it's not a threat modeling methodology in itself for identifying threats against a specific application design.
  • C. DREAD is a risk rating model (Damage, Reproducibility, Exploitability, Affected users, Discoverability) often used *after* STRIDE to prioritize identified threats, not a threat identification framework.

STRIDE Threat Modeling

A threat modeling framework developed by Microsoft that categorizes potential threats into six categories: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.

  • Used to identify threats against systems and applications.
  • Helps ensure comprehensive coverage of potential attack vectors.
  • Often used early in the Software Development Life Cycle (SDLC).

Memory trick: THREAT MODELING uses STRIDE to categorize, DREAD to rate, and ATT&CK to map attacks.

More Security Assessment and Testing questions