Reaching the crown jewels – how do we create impacts?
The means to achieving these target goals will involve using STRIDE to evaluate the components of the system. We will try to reason about the system to see how we can reach those crown jewels (usually by weakening or compromising security properties). During the evaluation process, we will look at the system within its ecosystem (as a functional part of a whole process) and try to understand how we can reach the crown jewels by compromising it.
Once the crown jewels have been identified, we will evaluate the components in terms of STRIDE to understand how they can allow us to reach the crown jewels.
STRIDE through the components to compromise properties
Tip
Some other methodologies exist to take care of this, but they are far beyond the scope of this book. If you are interested, you can refer to EBIOS (https://www.ssi.gouv.fr/en/guide/ebios-risk-manager-the-method/) or ISO/IEC 13335-2 (https://www.iso.org/standard...