How does threat modeling differ between roles in it

Assignment Help Computer Engineering
Reference no: EM133627000

Question: Threat modeling is an important process to help identify deficiencies in systems that are meant to keep assets secure. Using a framework like the Howard Threat Model while summarizing the attack provides an industry vetted model that allows for easy identification of incidents versus threats. Every cyber incident can be depicted in threat modeling scenarios, which provides an industry standard to communicate the characteristics of any threat. Threat modeling is an important practice for cybersecurity analysts because they must compare different forms of threats to identify common characteristics and build the most secure defense against threats. This activity will draw on important fundamentals we have explored previously, like the confidentiality, integrity, and availability (CIA) triad and adversarial mindset.

This activity relates directly to the final project, where you will be required to complete a threat model for your project scenario. Take advantage of feedback on this assignment to prepare you for your final project submission in Module Seven.

Prompt

Analyze the three breach case studies found in the three articles that are linked in the Reading and Resources section of Module Three of your course. Use this information to fill out the template and address the critical elements listed below.

Threat Modeling
To complet this assignment, first download the Stepping Stone One Template from the Stepping Stone assignment in Module Three of your course. Identify the elements of the Howard Threat Model by filling in the template for the case studies below.
Complete column for Target Breach thoroughly and accurately
Complete column for Sony Breach thoroughly and accurately
Complete column for OPM Breach thoroughly and accurately
Incident Analysis
Select one of the incidents from the table and analyze the following:
Which of the CIA triad is most applicable to the "Action" category of the selected incident? Explain your answer.
How can you use an adversarial mindset in analyzing the "Attackers" and "Objective" to inform the response to the attack?
Imagine you worked for the organization in the chosen incident and had used a threat model proactively. What changes could you have made to the organization to avoid the incident?
Threat Modeling Extension
Defend the need for performing threat modeling. How would you convince your supervisor that threat modeling is worth the time and resources needed to complete it?
Why is threat modeling an important tool for a security practitioner?
What organizational advantages beyond security controls might arise from this threat modeling exercise?
How does threat modeling differ between roles in IT (for example, testers-data mutations; designers-analyzing threats; developers-tracking data flow)?

Reference no: EM133627000

Questions Cloud

What human resources management activity : For the companies participating in this foundation, this is a form of what human resources management (HRM) activity?
How can i extend on information about this post : HORIS that are packed with sensors so they can relay the most up-to-date information down to the users. How can I extend on information about this post
Write a memo regarding improvement on professor teaching way : Write a bad news memo regarding improvements on Professor teaching way. Please use OABC and 5W2H format.
Vitamin and mineral supplement : How do the suggested intakes of the vitamins and minerals in the supplement compare with the current DRIs for these nutrients?
How does threat modeling differ between roles in it : How does threat modeling differ between roles in IT (for example, testers-data mutations; designers-analyzing threats; developers-tracking data flow)
What can you use to add dragging and dropping : What can you use to add dragging and dropping, resizing, and sorting methods to your web pages, as well as more animations and effects, animated color
Explain briefly and provide valid references : what happened, how much information was taken, the steps to remedy it, and the fallout. Please explain briefly and provide valid references
Calculate the takt time for the provided system data : To deliver the products to customer, there are four processes to go through in sequential manner. Calculate the Takt time for the provided system data.
Explain confirmation bias-egocentrism : Explain confirmation bias, egocentrism, and sociocentrism in regards to writing preparation.

Reviews

Write a Review

Computer Engineering Questions & Answers

  Mathematics in computing

Binary search tree, and postorder and preorder traversal Determine the shortest path in Graph

  Ict governance

ICT is defined as the term of Information and communication technologies, it is diverse set of technical tools and resources used by the government agencies to communicate and produce, circulate, store, and manage all information.

  Implementation of memory management

Assignment covers the following eight topics and explore the implementation of memory management, processes and threads.

  Realize business and organizational data storage

Realize business and organizational data storage and fast access times are much more important than they have ever been. Compare and contrast magnetic tapes, magnetic disks, optical discs

  What is the protocol overhead

What are the advantages of using a compiled language over an interpreted one? Under what circumstances would you select to use an interpreted language?

  Implementation of memory management

Paper describes about memory management. How memory is used in executing programs and its critical support for applications.

  Define open and closed loop control systems

Define open and closed loop cotrol systems.Explain difference between time varying and time invariant control system wth suitable example.

  Prepare a proposal to deploy windows server

Prepare a proposal to deploy Windows Server onto an existing network based on the provided scenario.

  Security policy document project

Analyze security requirements and develop a security policy

  Write a procedure that produces independent stack objects

Write a procedure (make-stack) that produces independent stack objects, using a message-passing style, e.g.

  Define a suitable functional unit

Define a suitable functional unit for a comparative study between two different types of paint.

  Calculate yield to maturity and bond prices

Calculate yield to maturity (YTM) and bond prices

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd