markdowneditor

Threat Model: [system or feature]

STRIDE threat model – assets, LxI scoring, acceptance

सॉफ़्टवेयर और इंजीनियरिंगमानकSTRIDEthreatmodel
एडिटर में खोलें.md डाउनलोड करें

उपयोग कैसे करें: Before shipping anything security-relevant. Score L x I honestly; an unmitigated risk list with no owner acceptance is a warning, not a model.

प्रीव्यू

Threat Model: [system or feature]

Structured security review – find the abuse cases before the adversaries do. Adapted from the STRIDE methodology.

FieldValue
System / feature[name]
VersionN.N
Owner@name
Reviewers@name, @name
DateYYYY-MM-DD
StatusDraft / In review / Approved

Scope

  • In scope: components, data flows, trust boundaries covered
  • Out of scope: what this review deliberately excludes

System overview

flowchart LR
    U[User] --> LB[Load balancer]
    LB --> API[API service]
    API --> DB[(Database)]
    API --> EXT[Third-party API]

Trust boundaries (where data crosses a privilege level): public internet -> LB, service -> database, service -> third party.

Assets

AssetSensitivityWhy it matters
e.g. user credentialsHighAccount takeover

Threats

Score each threat by STRIDE category. L = likelihood, I = impact (1-5), Risk = L x I.

IDThreatSTRIDEComponentLIRiskMitigationStatus
T-01e.g. stolen session token replayedSpoofingAuth3515Short TTL + rotationOpen
T-02

STRIDE: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege.

Assumptions & dependencies

What is relied on without verification: TLS configuration, third-party SLAs, managed-service security, upstream patching.

Unmitigated risks & acceptance

ThreatResidual riskAccepted byDateExpiry
@nameYYYY-MM-DDYYYY-MM-DD

Follow-ups

  • File tickets for every Open mitigation
  • Re-run this model after [trigger: major change / N months]

संबंधित टेम्पलेट