Threat modeling: The process of identifying, understanding, and addressing potential threats in a prioritized way. It involves creating a conceptual model of the system or application, including data flow and connectivity, and then identifying assets, threats, and vulnerabilities within this model. The purpose is to mitigate possible security risks during the design phase of a system rather than after deployment.
Categories: CC D5: Security Operations | CCSP D4: Cloud Application Security | CISM D2: Information security risk management | CISSP D1: Security and Risk Management | Security+ D2: Threats Vulnerabilities and Mitigations | SSCP D3: Risk Identification Monitoring and Analysis
Related Articles: