Reviewing the PASTA threat model and use cases
Threat modeling is a critical part of any SOC environment and team. It can be used as discussed to identify risks and gaps and for strategy, or it can be used for informational campaigns. Like all things, there are multiple different types of threat models, and there is no one size fits all for the types. The first threat model that we’ll analyze and talk through use cases is the Process for Attack Simulation and Threat Analysis (PASTA) threat model. PASTA is a risk-centered threat model that combines risk analysis and the surrounding context into your risk mitigation and security strategy. In development terms, thinks of PASTA as an incremental development process where you constantly go through cycles and make changes without having to start at the beginning of the model again. The main steps of the PASTA method are as follows:
- Define the objective: This means setting the overall purpose for the threat model. This could...