QuestionQ50

Security Architecture

A company wants to perform threat modeling on an internally developed, business-critical application. The Chief Information Security Officer (CISO) is most concerned that the application should maintain 99.999% availability and authorized users should only be able to gain access to data they are explicitly authorized to view. Which of the following threat-modeling frameworks directly addresses the CISO’s concerns about this system?

Explanation

STRIDE categorizes threats into Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. Denial of Service maps directly to the CISO's availability requirement, while Information Disclosure and Elevation of Privilege map to the requirement that users only access data they are explicitly authorized to view. CAPEC catalogs attack patterns, ATT&CK maps adversary tactics/techniques, and TAXII is a threat-intel sharing protocol — none organize threats by these confidentiality/availability categories the way STRIDE does.

Community Discussion

No comments yet. Be the first to start the discussion!