Files
TechRadarAJR/radar/2019-11-01/stride-threat-modeling.md
2019-11-06 08:24:56 +01:00

20 lines
629 B
Markdown

---
title: "STRIDE Threat Modeling"
ring: trial
quadrant: methods-and-patterns
---
STRIDE is a model of threat groups that helps to identify security threats to any application, component or infrastructure.
The acronym stands for:
* Spoofing
* Tampering
* Repudiation
* Information disclosure
* Denial of service
* Elevation of privilege
AOE is applying the threat model in collaborative sessions using the [Elevation of Privilege Card Game](https://social.technet.microsoft.com/wiki/contents/articles/285.elevation-of-privilege-the-game.aspx) which helps to spark imagination and makes threats more tangible.