STRIDE Threat Modeling

trial

STRIDE is a model of threat groups that helps to identify security threats to any application, component or infrastructure.

The acronym stands for:

  • Spoofing
  • Tampering
  • Repudiation
  • Information disclosure
  • Denial of service
  • Elevation of privilege

AOE is applying the threat model in collaborative sessions using the Elevation of Privilege Card Game which helps to spark imagination and makes threats more tangible.