-
Book Overview & Buying
-
Table Of Contents
Threat Modeling Best Practices
By :
It’s one thing to know what can go wrong, but it’s entirely another to assess how likely it is to happen and what impact it will have on the organization. This is where risk evaluation ties into the output from a threat modeling exercise. Once a threat has been identified in the threat model, it needs to be evaluated for the risk it poses to the organization, allowing us to prioritize what really matters. Several frameworks or processes exist, including simply looking at historical or empirical data of risks that have materialized in the organization or similar ones. However, here are a few other high-level risk evaluation methods to be familiar with.
A qualitative risk assessment is a structured approach to evaluating risks. It helps organizations assess the severity of threats by combining the likelihood of a threat materializing with the potential impact of an attack, often called the “basic method.”...
Change the font size
Change margin width
Change background colour