Threat Modeling and Risk Management

Tony Ucedavélez, Marco M. Morana · 2015

The main goal of the threat analysis is to unveil how threats affect web applications and identify the probability that these web applications might be attacked in the future. This probability can be factored in the calculation of risk probability; the probability of a threat source to exploit vulnerabilities to cause an impact on assets. Threat analysis can leverage the analysis of cyber-threats from threat intelligence sources and capture the information about these threats by building a threat library. For organizations that have adopted risk-based threat modeling, the determination of the likelihood and impact of an exploit can be analyzed only after modeling the attacks. The last step of the security incident response consists of analyzing how the incident response procedures were applied and identifying opportunities for improving the current procedures based on the lessons learned during the security incident handling.

Read the paper · More papers on PaperTik