The strategic threat modeling process
The threat modeling process is a systematic and structured set of steps that facilitate the planning, provisioning, and optimization of security operations. It consists of breaking down the necessary elements that can be used to ensure and enforce protection. Those elements include the following:
- Identifying assets: Any resource that can be compromised or wanted by an adversary.
- Risk and vulnerability assessment: The ability to highlight system flows that, if exploited, can compromise an organization's assets.
- Adversaries and threats: The different adversary groups that have targeted or are targeting assets in the organization's profile, their Tactics, Techniques, and Procedures (TTPs), and all existing threat vectors that they can use to exploit the system flows.
The security or threat intelligence analyst must then map these three elements to create a basic threat model that can help implement a solid and effective...