Skip to content
IIBA.org How to Implement a Threat Modelling Approach in 6 Steps

How to Implement a Threat Modelling Approach in 6 Steps

Key Takeaways

To enhance organizational cybersecurity, adopt this six-step threat modelling approach:

  • Define security requirements aligned with organizational policies
  • Create application diagrams and attack trees for vulnerability analysis
  • Develop use cases tailored to the organization’s threat profile
  • Identify, rank, and manage risks using tools like STRIDE and OWASP
  • Collaborate with cybersecurity experts to establish mitigation strategies
  • Test and validate systems with robust security testing methods
 
Disclaimer: The views and opinions expressed in this article are those of the author and may not reflect the perspectives of IIBA.

As more organizations become cloud-based and virtualized, they face a greater risk of cyberattacks. The use of mobile and Internet of Things (IoT) devices has enabled a massive surge in the threat landscape. In the past year, hospitals, tech companies, critical infrastructure companies, and hotels have all been affected by at least one ransomware attack, in which hackers encrypt critical files and hold organizations hostage until a ransom is paid.

The recurring data breaches we've witnessed must drive organizational change. One practical application of this is for business analysis professionals to implement a threat modelling approach. This article discusses six steps to do so. 

Integrating Threat Modelling into Business Analysis for Secure Development

The Cybersecurity and Infrastructure Security Agency (CISA) defines cybersecurity as “the art of protecting networks, devices, and data from unauthorized access or criminal use and the practice of ensuring confidentiality, integrity, and availability of information.”

Business analysis professionals may not be responsible for implementing cybersecurity measures to protect networks, environments, data, or devices. That said, they do play an important role in maintaining an organization’s security. They must consider cybersecurity as a vital part of any endeavour or analysis they undertake.

To this end, the threat modelling approach can be built into the business analysis phase of product development to create a strong cybersecurity posture for organizations. Threat modelling is a structured approach to securing any system by actively identifying potential risks and vulnerabilities and applying mitigation methods. By building this approach into business analysis, secure systems can be built from the start.

Cyber threat modelling can be used throughout the system development lifecycle (SDLC), including requirements definition, analysis and design, implementation, testing, and operations and maintenance (O&M). However, it’s especially important for design analysis and testing, where threat scenarios can be created and used to design and test devices, applications, and systems.

To successfully enable strong product development, business analysis professionals must undertake the threat modelling approach during all phases of the business analysis process, starting from requirements elicitation to the final delivery of the product. 

Cybersecurity-Blog-Graphic-2.png
Figure 1. Threat Model Frameworks and Methodologies

Step 1: Define Security Requirements

The business analysis professional responsible for eliciting security requirements for a project or a new solution must comply with the company’s cybersecurity policies, tools, and practices. The requirements elicitation approach may involve conducting interviews, workshops, Joint Application Development (JAD) sessions, or collaborative workshops to gather user requirements, perform job shadowing, and analyze existing documentation.

Business analysis professionals may also gather requirements for cybersecurity solutions and initiatives based on the organization's needs and objectives, and in adherence to industry-standard security requirements and potentially cybersecurity regulations.

Step 2: Analyze the Application and Create Application Diagram

A business analysis professional gathers requirements and works with business stakeholders, including security professionals, to analyze the application and create application diagrams. These provide a high-level, asset-centric view of systems along with the foundation for creating attack trees. Application diagrams act as a blueprint for building secure systems, while attack trees help in identifying and mitigating vulnerabilities.

An attack tree is a methodological, graphical representation of an attack from the attacker’s perspective, illustrating the possible origins and paths of attacks. Stakeholders (e.g., security professionals, business analysis professionals, risk management professionals) can build attack trees to model potential attacks on specific components or interactions. These will later be used to re-engineer business processes by identifying vulnerabilities and then prioritizing defensive measures.

Step 3: Develop Use Cases

The business analysis professional captures the organization’s use cases, which reflect its unique requirements and threat profile. The threat environment is dependent on the industry vertical in which the business operates, the types of assets the company owns, the location of operations, applications, the cloud environment used by the business, and the regulatory environment. Businesses can ensure stronger security by following a comprehensive approach to business analysis.

Step 4: Identify and Rank Potential Threats

A project manager conducts risk analysis, maintains a list of detected risks, and evaluates risks in terms of impact and likelihood. Creating a unified risk management framework that includes business and cybersecurity risks is critical, as it ensures all risks are evaluated from both a technical and business approach.

Involving business analysis professionals in project risk analysis is crucial for a complete approach to cybersecurity. They can provide valuable insights into business operations, identify potential vulnerabilities, and translate technical security needs into actionable requirements.

Threat modelling tools can be used to generate threat scores and data that can calculate risk. These include:

  • Microsoft’s Threat Modeling Tool, called STRIDE (Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, and Elevation of privilege), for creating and visualizing threat models
  • Open Web Application Security Project (OWASP), an open-source tool
  • SD Elements, which automates threat modelling and integrates with security requirements management

A component of the Microsoft Security Development Lifecycle (SDL), STRIDE helps software architects identify and mitigate potential security issues early, when they’re easier and more cost-effective to resolve. Microsoft’s Threat Modeling Tool, which incorporates the STRIDE approach, can be downloaded for free by teams building new systems or updating existing ones.

Cybersecurity-Blog-Graphic-1.png
Figure 2. STRIDE Modelling for Online Store

Step 5: Establish Mitigation Strategies

To ensure effective threat mitigation, business analysis professionals should engage cybersecurity experts as key stakeholders when brainstorming strategies and creating a plan. These specialists provide essential expertise in identifying and addressing cyber threats. They will implement appropriate security controls and work to enhance the organization's security posture throughout the project lifecycle.

Step 6: Test and Validate

Once the business analysis professional has identified the areas, assets, or threats most critical to the organization, the next steps can be planned in order of need. These can include firewall updates, role-based access control, API security, encryption implementation, or multi-factor authentication to address a threat.

Test techniques such as Static Application Security Testing (SAST), unit testing, Dynamic Application Security Testing (DAST), and functional and penetration testing are used to detect any remaining vulnerabilities in the applications and systems.

Building Security In: The Analyst's Role

Threat modelling should be integrated early into an organization's product development lifecycle. This allows the organization to progressively refine its threat models and reduce risk as it develops new applications. Business analysis professionals play a crucial role in this process, helping to facilitate threat modelling in the initial project phases to ensure a secure final product.

If you're looking to strengthen your cybersecurity expertise, now is a great time. This October, you can save 20% on the Certificate in Cybersecurity Analysis (IIBA-CCA) exam. Don’t miss out—register today.


About the Author
Author.jpg

Priyanka Mansata has been a business analyst/technical writer at Fortune 500 companies and has worked on US federal projects. She has an MBA and holds the CBAP, PMP, CompTIA Security+, and CSM certifications. She writes on technical and business topics such as cybersecurity, IoT, and how an understanding of the field of business analysis is critical in adding value to organizations.  

Must Read Blogs From IIBA

The Importance of Self-Reflection in Business Analysis and Cybersecurity

Think you have a solid grasp on cybersecurity? There’s more beneath the surface. Explore how self-reflection can reshape your understanding of threats and improve decision-making in business analysis.
Read the Blog

From Cybersecurity to Storytelling

Here are three key takeaways from the latest edition of BA Digest.
Read the Blog

Cybersecurity Awareness Month: What Business Analysis Professionals Need to Know

October is Cybersecurity Awareness Month. With rising cyber threats, business analysis professionals must stay informed and engaged.
Read the Blog