Threat Modeling Guide: How to Identify Digital Risks in International Development Projects
Key Guides
Bonn: Deutsche Welle DW Akademie (2020), 52 pp.
"Each section of this guide will explore another dimension of digital security—assets, attackers, risks and likelihood—and address these key questions: What do I want to protect? Who are my attackers? Is my attacker able to succeed? How likely is it that my attacker will succeed? Threat modeling consists of two types of assessments: Firstly, an analysis of the project’s environment (questions one and two). Secondly, an estimation of the likelihood that potential attacks will really happen (questions three and four). To prepare for threat modeling, we have added a “question zero” for project managers: Who are we and what do we do? This helps to establish a clear understanding of the entire project, with all of its workflows and challenges that employees face in their day-to-day work environment. A threat model is the basis for a digital security concept that should be developed along with IT experts so that your concept is both technically sound and practically enforceable. Having a clearly defined list of assets and their vulnerability empowers employees to protect them with appropriate countermeasures, and educates them on risks. This will increase the efficacy of a security concept in practice." (Executive summary)
WHY IS DIGITAL SECURITY CRUCIAL FOR YOUR WORK? 8
Your data makes you an interesting target, 9
Why is it up to you, not the IT department? 9
Protecting your daily work, 9
HOW DO YOU USE THIS GUIDE? 10
WHAT IS THREAT MODELING? 12
Risk assessment,13
Four threat dimensions to consider, 13
Applying threat modeling to your work, 14
Question zero: Knowing your environment, 15
THREAT MODELING, STEP BY STEP, 16
Question zero, 17
General advice: Include a threat model in your project plan, 17
Going deeper: Explore your project, 18
Question 1: What do we want to protect? 22
Question 2: Who are our attackers? 25
How external attackers are connected, 26
How data is exchanged amongst different entities, 27
The human factor and internal resistances, 29
Question 3: Are our attackers able to succeed? 32
Question 4: How likely is it that our attackers will succeed? 40
OUTCOME: TOWARDS YOUR OWN DIGITAL SECURITY CONCEPT, 44
Your data makes you an interesting target, 9
Why is it up to you, not the IT department? 9
Protecting your daily work, 9
HOW DO YOU USE THIS GUIDE? 10
WHAT IS THREAT MODELING? 12
Risk assessment,13
Four threat dimensions to consider, 13
Applying threat modeling to your work, 14
Question zero: Knowing your environment, 15
THREAT MODELING, STEP BY STEP, 16
Question zero, 17
General advice: Include a threat model in your project plan, 17
Going deeper: Explore your project, 18
Question 1: What do we want to protect? 22
Question 2: Who are our attackers? 25
How external attackers are connected, 26
How data is exchanged amongst different entities, 27
The human factor and internal resistances, 29
Question 3: Are our attackers able to succeed? 32
Question 4: How likely is it that our attackers will succeed? 40
OUTCOME: TOWARDS YOUR OWN DIGITAL SECURITY CONCEPT, 44