-
Book Overview & Buying
-
Table Of Contents
-
Feedback & Rating
Threat Modeling Best Practices
By :
In this chapter, we will discuss what we should do with the risks that are identified from threat models and various processes in an organization. Generally, the overall risk can be calculated from the impact and likelihood of an identified threat. But every organization will treat that risk differently depending on their environment, industry, and regulations. Regardless of how the risk is handled, each organization needs to keep an inventory of the outstanding risks and manage them. We will discuss how risk is evaluated, categorized, and classified following some of the common methodologies and best practices. We’ll then dive into how risk is assessed and managed.
Identifying risk is only part of the overall risk management solution. The organization needs to determine what to do with that risk. In some cases, they will remediate or mitigate the risk, thereby reducing the risk level. Or they may look to transfer or accept the...
Change the font size
Change margin width
Change background colour