Threat Modeling: Diving into the Deep End

  • Authors:
  • Jeffrey A. Ingalsbe;Louis Kunimatsu;Tim Baeten;Nancy R. Mead

  • Affiliations:
  • Ford Motor Company;Ford Motor Company;Ford Motor Company;Carnegie Mellon University

  • Venue:
  • IEEE Software
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

Ford Motor Company is introducing threat modeling on strategically important IT applications and business processes. The objective is to support close collaboration between the IT security group and its internal business customers in analyzing threats and better understanding risk. For this purpose, a core group of security personnel have piloted Microsoftís Threat Analysis and Modeling process and tool on a dozen targets. This article discusses this process, along with the challenges and successes of its ongoing deployment in the organization. This article is part of a special issue on Security of the Rest of Us.