In your own words explain (a) what is threat modeling, and (b) why it is importa
ID: 394341 • Letter: I
Question
In your own words explain (a) what is threat modeling, and (b) why it is important for an enterprise to address threat modeling extensively. Please state your answer in a 1-2 page paper in APA format. Include citations and sources in APA style.
Note: Please mention with references and intext-citations.
Grading Criteria Assignments Maximum Points Meets or exceeds established assignment criteria 40 Demonstrates an understanding of lesson concepts 20 Clearly presents well-reasoned ideas and concepts 30 Uses proper mechanics, punctuation, sentence structure, spelling and APA structure. 10 Total 100Explanation / Answer
(a) Threat Modeling - It is the process of identifying, prioritizing and analyzing the potential threats to the technology applications or software development projects of the organizations. The threat modeling applies throughout the lifecycle of software development lifecycle of a project at various stages. The kind of threats, their impact on the system and preventive measures to deal with threats are part of the threat modeling process.
Threat modeling process involves identification of organizational assets for securing them. Overview of the functions, flow of data and linkages are mapped to discover potential vulnerabilities to the system. The system security is studied at the component level to take steps for securing each of them.
(b) It is important for organizations to address threat modeling extensively to secure and protect the software development and applications of the organization. Threat modeling is a structured approach towards eliminating the risk towards the security of the system. There are constant changes to the software applications by a firm. Threat modeling is a systematic process to evaluate the risks and ways for preventing the threats to the system in a timely manner. Threat modeling is an aid for the organization to develop the resources and train the professionals to deal with potential threats. Threat modeling finds out the most serious threats which require attention and action. It helps in regular checks of the system for securing and identification of threats beforehand.
Sources referred for the above answer are (ThreatModeler Home)
Threat Modeling: Designing for Security( Adam Shostack)