Threat modelling early in software architecture

Vaisala is aligning its secure development lifecycle practices with IEC 62443-4-1. Threat model is an essential tool to steer and prioritize the product’s security implementation throughout the product’s lifecycle.
Movial conducted a threat model together with the development team in workshops. We evaluated threats that could compromise confidentiality, integrity or accessibility of the device using a STRIDE-based threat modelling methodology, and proposed mitigations for identified threats.
Having a threat model early in the development helped guide the device software architecture design by taking the identified threats into account for building proper SECURE-BY-DESIGN, DEFENCE-IN-DEPTH solutions - mitigating identified threats even before the implementation work began.
Suosittelija:
Jari Rasinen