Member-only story
CISSP Domain 3 Notes - Security Architecture and Engineering
Research, Implement and manage Engineering processes using secure design principles
Threat Modelling
Prioritizing threats against an organisation’s valuable assets.
3 common Threat Modelling Techniques to Identify Threats:
- Focused on Assets
- Focused on Attackers
- Focused on Software
Threat Modelling Approach
Process for Attack Simulation and Threat Analysis (PASTA)
A seven-stage threat modelling methodology. PASTA is a risk-centric approach that aims at selecting or developing countermeasures in relation to the value of the assets to be protected.
Next step after Threat Modelling is ‘Reduction Analysis’ (Decomposition of application, system or…