Board logo

subject: How To Perform Threat Modeling [print this page]


Fortunately, threat modeling is a simple process. It takes time to do it right, but this time is well spent if it uncovers vulnerabilities in proposed or existing systems and allows you to protect systems from those threats. The threat modeling process consists of the following steps:

1. Assemble a team. The team should be composed of people who know the current network and its systems well; people who know the proposed new hardware, software, or infrastructure; people who use the systems; and informed outsiders.

Team membership should not be restricted to certification provider IT professionals. Computers, appli cations, and networks are used by many people within your organization, and these people often know the shortcuts or quick ways of doing things and the workarounds that they, as users, tend to use. Knowledge of common user prac?tices can suggest new areas for threat investigation.

2. Understand the process. Use existing and new flow charts and diagrams to thor? oughly document the process. You want to know how data flows through the sys? tem, where all components are located, who administers them, and who has access to them. Because current processes are often incompletely documented, this is a good opportunity to discover more information about the systems, and the process might lead to discovering other areas where security design is necessary.

3. Determine threats. Use brainstorming techniques to list all possible threats, no matter how bizarre they might sound. At this point, every possible threat men? tioned should be recorded.

4. Rank threats by risk. This is the point at which you determine the threats that are most likely to damage systems or allow successful intrusion. Like a business impact analysis, the ranking of threats allows you to calmly deal with the most likely scenarios first.

5- Determine a response for each threat. Should you respond? How much effort should be spent? What mitigation techniquessuch as 70-290 Exam data encryption, smart cards, VPN, hardening techniques, and so onare already in place to deal with this threat? Are they adequate?

6. Use technology and security processes to mitigate the threat. After threats worthy of response have been ranked and mitigation techniques have been designed, choose and implement the techniques that can do the job.

How to Design an Incident Response Process

No matter how careful you are in implementing preventative processes and techniques, no matter how extensive your threat modeling is, and no matter how well you respond to an attack and prevent its MCSE Exam success, there will always be the possibility that an attack on your system will succeed. Furthermore, an attack does not have to succeed to be of interest. Is an increase in port scanning the prelude to a directed attack? Are a number of Web defacements indicative of a possible elevation in politically motivated attacks on government targets? Your security design needs to be able to respond to both successful attacks and activities on your system that may indicate an attack is in progress.

by: endeavor03




welcome to loan (http://www.yloan.com/) Powered by Discuz! 5.5.0