StudyToCert

All certifications / CISSP / Lessons

ISC2 CISSP 2024 outline · Domain 1: Security & risk management

Threat modeling methodologies (STRIDE, PASTA) and supply chain risk management

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Threat modeling is a structured way to find and prioritize threats to a system, ideally during design when fixes are cheapest. It answers four questions: what are we building, what can go wrong, what are we going to do about it, and did we do a good job. You usually start by decomposing the system into a data flow diagram showing external entities, processes, data stores, data flows and trust boundaries, which are the points where data passes between areas of different trust, such as from the internet into a web tier or from an application into a database.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISSP for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISSP study plan