Difference between revisions of "Threat Model"

From Open Risk Manual
(Created page with "== Definition == A '''Threat Model''' is a formal representation of the risk landscape faced by an individual or organization that explicitly focuses on risks that can be clas...")
(No difference)

Revision as of 10:27, 14 October 2021

Definition

A Threat Model is a formal representation of the risk landscape faced by an individual or organization that explicitly focuses on risks that can be classified as threats.

Classification

  • Attacker centric, focusing on Threat Actor identification and analysis
  • Asset centric, focusing on Asset identification and analysis
  • System centric