Glossary · OT cybersecurity
Threat modeling
Also known as: Threat model, Threat analysis
German: Bedrohungsmodellierung
In security engineering, threat modeling is the structured analysis of a system's architecture, data flows, trust boundaries and entry points to identify potential threats, the assets they target and the countermeasures needed. IEC 62443-4-1 requires a threat model for industrial automation products.
- OT security
In one sentence
Threat modeling analyzes a system's architecture, data flows and trust boundaries to identify threats and the countermeasures needed.
Example
The threat model for a new edge gateway shows a trust boundary between the OT network and the cloud connection, and identifies spoofed cloud commands as a threat requiring mutual authentication.
How it applies
- Product development: The threat model is built early from data flow diagrams and updated with each significant design change. Methods such as STRIDE (spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege) help structure the search for threats.
- Engineering: Identified threats become security requirements and test cases, which creates traceability from threat to countermeasure to verification.
- Safety: Threat models should mark data flows that affect safety functions or safety parameters, so that security and safety analyses can be linked.
- Documentation: Threats that the product does not mitigate itself become assumptions about the environment. These must appear in the security guidelines as operator measures, for example "operate only in a protected zone"; otherwise the threat model's conclusions never reach the user.
Threat modeling vs. security risk assessment
Threat modeling is usually done by the product supplier on a product design. The Security risk assessment is done for an installed system by or for the asset owner and sets target security levels.