Step 1: Identify security objectives.
The process of identifying security objectives is one that begins with a
review of the application's needs and different procedures that may be
used in the future to design details, avoid vulnerabilities, etc.
Step 2: Identify assets and external dependencies.
This process entails identifying assets and evaluating the ones that need
to be safeguarded (techtarget.com).Anything suggested as business-
critical can be considered an asset in most firms
(techtaget.com).According to Techtarget.com, some common assets
include, customer data/payment information, corporate financial data,
proprietary software code, etc.
Step 3: Identify trust zones.
In some instances, this is a combination of one or more network segments
that must have policies in place to control inbound and outbound
traffic.The zones and interfaces used to access the zones must be
trusted in order to allow data and information flow to the trusted
individuals.
Step 4: Identify potential threats and vulnerabilities.
This step involves identifying and evaluating the risk that the company
may face.According to techtarget.com, to identify possible attackers
who may try to infiltrate the network, use an adversary-based security
plan.These models may outline attackers such as malicious insider,
attacks towards hardware software and etc.
Step 5: Document your threat model.
In reference to designing, implementing, troubleshooting, lessons learned,
documentation is very important.Therefore, documenting the threat
model is just as important.These threats must be documented in order to
prevent vulnerabilities, which can impact a business in a negative
manner.
According to Eric Dosal, operational security measures are employed to
address the "human component" that is always present in any
cybersecurity plan.They can be used to establish expectations and to
spell out the consequences of non-compliance (Dosal, Eric).Meanwhile,
physical and technical controls are aimed at preventing unauthorized
entry, whether through physical barriers or technological solutions that
prevent in-person or remote access (Dosal, Eric).Evaluating physical,
logical and administrative threats in most instances may be done in
conjunction.All three of them can be used to establish procedures and
prevent threats and identify vulnerabilities.
Dhamankar, Rohit.(08 July 2021).5 steps to implement threat modeling
for incident response.
https://www.techtarget.com/searchsecurity/post/5-steps-to-implement-
threat-modeling-for-incident-response
Dosal, E. (1 October 2019).What are administrative security
https://www.compuquip.com/blog/what-are-administrative-security-
controls