Published: 01 June 2023
Summary
This 2-minute Consult the Board survey summary features perspectives from 11 Information Risk Management Research Board members regarding their scope and implementation of threat modeling. It highlights members’ threat modeling frameworks, tools, and the depth of its integration into their software development pipelines.
Included in Full Research
Overview
What is the level of threat modeling adoption and use in members’ software development practices?
An equal number of respondents (6 of 11) use the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) framework and the Spoofing, Tampering, Repudiation, Information disclosure, Denial of service and Elevation of privilege (STRIDE) framework for threat modeling.
Clients can log in to view the entire
document.
Analysts:
Consult the Board Research Team