Benefits of threat modeling

For any given project, it is always helpful to understand the threats that may hinder the overall progress. Threat modeling does the exact same thing. Some benefits of threat modeling are :

  • Threat modeling produces software that is inherently secure by design—if the threat modeling is done right in the design phase, then the end product will become inherently secure against most common potential threats.
  • Threat modeling allows us to think and discuss product security in a more structured way—instead of discussing security threats in an ad-hoc manner, threat modeling offers a more formal and structured way of enumerating and documenting security threats.
  • Threat modeling permits development teams to effectively identify and define security flaws early in the SDLC process.
  • Threat modeling allows us to document and share application security knowledge—with technology upgrading at a rapid pace, the threat landscape is changing at a  fast pace as well. Ongoing threat modeling exercises will help ensure that the latest threats are being considered and anticipated for designing mitigating controls. 
  • Threat modeling increases customer confidence from a security perspective— documented evidence of the threat modeling process being followed would certainly boost customer confidence in the security of the system delivered.
  • An ongoing threat modeling exercise would help reduce the overall attack surface area.
  • Threat modeling can help in quantifying security controls, making it more practical to align with the security budget.
..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
3.14.6.194