From Application Security and Development Security Technical Implementation Guide
Part of ASDV-PL-003230
Associated with: CCI-003256
Threat modeling is an approach for analyzing the security of an application. It is a structured approach that enables you to identify, quantify, and address the security risks associated with an application. Threat modeling is not an approach to reviewing code, but it does complement the security code review process.
This requirement is meant to apply to developers or organizations that are doing application development work. If the organization operating the application is not doing the development or is not managing the development of the application, the requirement is not applicable. Review the threat model document and identify the following sections are present: - Identified threats - Potential vulnerabilities - Counter measures taken - Potential mitigations - Mitigations selected based on risk analysis Review the identified threats, vulnerabilities, and countermeasures. Countermeasures could include implementing application firewalls or IDS/IPS and configuring certain IDS filters. Review the application documentation. Verify the architecture and components of the application match with the components in the threat model document. Verify identified threats and vulnerabilities are addressed or mitigated and the ISSO and ISSM have reviewed and approved the document. If the described threat model documentation does not exist, this is a finding.
Establish and maintain threat models and review for each application release and when new threats are discovered. Identify potential mitigations to identified threats. Verify mitigations are implemented to threats based on their risk analysis.
Lavender hyperlinks in small type off to the right (of CSS
class id
, if you view the page source) point to
globally unique URIs for each document and item. Copy the
link location and paste anywhere you need to talk
unambiguously about these things.
You can obtain data about documents and items in other
formats. Simply provide an HTTP header Accept:
text/turtle
or
Accept: application/rdf+xml
.
Powered by sagemincer