Step 1: Identify security objectives
What I know about Step 1 one of threat modeling is to understand the
security requirements and identify possible threats and how they flow to
achieve objectives. What you should consider if there are any specific
compliance or security-related requirements that are a part of the
business objectives."
It's imperative that you keep your data and applications safe and secure
by Enforcing the CIA triad:
• Confidentiality. This involves safeguarding data.
• Integrity. Protecting data from unauthorized access.
• Availability. Providing essential services even in the face of attack."
"
Step 2: Identify assets and external dependencies
What I know about the second step is that any unauthorized access to
assets such as data, code, and system information are the reason why
threats occur. The security architect is responsible for identifying a list of
assets to be protected from potential attackers. Another important task is
that they should identify external dependencies as well which may or may
not be part of code, but may pose a threat to the system."
Step 3: Identify trust zones
I believe that all these steps are important, however this and step 4 are
the most important due to the fact that in this step an Architects need to
identify a trust zone and its entry and departure points. They also will
need to documentation and utilization of this data flow diagram
information with privilege boundaries is essential. Such as a manual of a
hardening tool; much like step by step on how, what and where, they
have this implemented.
Step 4: Identify potential threats and vulnerabilities
This step is very important as well because, in addition to searching for
risks using STRIDE, examine dangers by utilizing SolarWinds as well as
running tenable Nessus scans on against base lines or STIGS if you will
that would have an overall negative impact on your system."
"
Step 5: Document threat model
Here is the Final step and this explains the importance of threat modeling
and the benefits in doing so.
• Helps identify, enumerate, communicate and understand threats and
mitigations
• Protect application assets
• Prioritize security improvements
• Provide a deep understanding of product and components
• Enables informed functionality vs. security trade-off decisions
Threat Modeling reinforces the notion that security efforts should be
focused on those areas that can cause the most harm. It is not role- or
technology-specific, but rather a way of thinking about managing
technology risk.
References
What Is Threat Modeling and How Does It Work? | Synopsys
Techtarget.com/searchsecurity/post/5-steps-to-implement-threat-
modeling-for-incident-response