Threat Modelling
What is Threat Modelling?
A structured approach for identifying, quantifying, and addressing security threats to a system or application. Threat modelling analyses potential attack vectors and helps prioritise security controls during the design phase.
Terms that appear alongside threat modelling
Each of these is named in at least one of the same controls as threat modelling. The number is how many controls name both.
- secure coding 9 shared controls
- owasp 8 shared controls
- security testing 6 shared controls
- code review 5 shared controls
- nist 4 shared controls
- vulnerability 4 shared controls
- risk assessment 4 shared controls
- compliance 3 shared controls
Frameworks that govern threat modelling
What the standards actually require on threat modelling
Requirements naming threat modelling across 6 standards, quoted from the control text.
Per OWASP ASVS V1: ensure verified application architecture + secure design + threat modelling. Requirements include (a) maintain documented secure software development lifecycle (SDLC) including security activities at requirements + design + implementation +...
OWASPASVS-1 · Architecture, Design and Threat Modelling (V1) →Per OWASP DSOMM Implementation dimension: implement secure software development practices. Requirements include (a) maintain secure coding standards aligned to language + framework + with developer guidance + (b) conduct threat modelling at design phase + revi...
DSOMM-2 · Implementation Practices, Secure Coding, and Threat Modelling →Perform threat modelling to identify potential threats and enumerate mitigating controls, covering both the running application and the artefacts and pipeline that produce it.
ASBv3-DS-1 · Conduct threat modeling →Software development shall follow a secure SDLC integrating threat modelling, secure coding, code review and security testing prior to release.
CON.8 · Software Development →Architecture Analysis. Threat modelling/architecture analysis using STRIDE or an equivalent method is performed so design-level risks are identified.
AA2.1 · Perform architecture analysis using STRIDE or equivalent →X.805 Clause 8 defines 5 Threat Categories that the X.805 Security Architecture is designed to mitigate + provides a Threat-Dimension Countermeasure Matrix linking each threat to specific Dimensions.
X805-Threats-Destruction-Corruption-Removal-Disclosure-Interruption-72Cell-Matrix-Application · ITU-T X.805 5 Threat Categories - Destruction + Corruption + Removal + Disclosure + Interruption + Threat-Dimension Countermeasure Matrix + 72-Cell Matrix Application + STRIDE + MITRE ATT and CK + Network Modular Risk Assessment →Questions people ask about threat modelling
What is Threat Modelling?
Why is Threat Modelling important for compliance?
Which compliance frameworks address Threat Modelling?
Where can I learn more about Threat Modelling?
See how Threat Modelling applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.