Threat modeling is a structured way of thinking about what could go wrong with a system before attackers find out for you. You describe the system, identify threats against it, decide which matter most, and plan controls. It is most valuable early, during design, when changing the architecture is cheap, but it also helps when reviewing existing systems or major changes. Security+ touches threat modeling in several places: threat actors and vectors, secure development, risk management and attack frameworks. The core skill is asking 'who would attack this, how, and what would it cost us?'
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.