Question

In: Computer Science

WEEK 3 DISCUSSION# 4 ANSWER THE FOLLOWING : 1: Fully explain how to use one of...

WEEK 3 DISCUSSION# 4

ANSWER THE FOLLOWING :

1: Fully explain how to use one of the threat modeling tools

2: What are the benefits or issues with Microsoft’s Threat Modeling process and tool?

Solutions

Expert Solution

`Hey,

Note: If you have any queries related the answer please do comment. I would be very happy to resolve all your queries.

1)

Step 1: Identify the assets (database server, file servers, data lake stores, Active Directory, REST calls, configuration screens, Azure portal, authenticated and anonymous web user, Azure AAD client apps, database users, DB administrators)

Step 2: Outline details of architecture on which the valuable asset is being processed. It may include the software framework, version and other architectural details (ASP.net web application connection to cloud data stores and third-party services using JWT tokens).

Step 3: Break down the application regarding its process, including all the sub-processes that are running the application. We create a data flow diagram (DFD).

Step 4: List identify threats in a descriptive way to review to process further.

Step 5: Classify the threats with parallel instances so that threats can be identified in the application in a structured and repeatable manner.

Step 6: Rate the severity of the threat.

2)

The Microsoft Threat Modeling Tool makes threat modeling easier for all developers through a standard notation for visualizing system components, data flows, and security boundaries. It also helps threat modelers identify classes of threats they should consider based on the structure of their software design.

Kindly revert for any queries

Thanks.


Related Solutions

WEEK 4 DISCUSSION #3 ANSWER THE FOLLOWING QUESTIONS BELOW: 1: Do you need to identify and...
WEEK 4 DISCUSSION #3 ANSWER THE FOLLOWING QUESTIONS BELOW: 1: Do you need to identify and manage every risk to an organization or are there risks that don’t matter? Explain why or why not and provide cases for each. 2: Read “Envisioning Risk – A Systematic Framework for Risk Visualization in Risk Management and Communication Why or why not it is important to be able to visualize risk? How can it help an organization understand risk?
WEEK 2 DISCUSSION ANSWER ANY TWO OF THE FOLLOWING IN 2-3 PARAGRAPHS OF EACH QUESTION. 1:...
WEEK 2 DISCUSSION ANSWER ANY TWO OF THE FOLLOWING IN 2-3 PARAGRAPHS OF EACH QUESTION. 1: The Report of the Task Force on Private Security states, “There is virtually no aspect of society that is not in one way or another affected by private security.” Is that still true today? Why or why not. 2: Discuss the different security concerns for different industries and why there is a difference between them. 3: What's the NIST Cybersecurity Workforce framework and why...
Unit 1-3 Discussion: Please answer one or more of the following questions. 1) For what data...
Unit 1-3 Discussion: Please answer one or more of the following questions. 1) For what data in your professional or personal life would it be useful to construct a frequency table or histogram? If you give this some thought, you should be able to identify several sets of data. 2) After using the formula for determining the value of P16 (the 16th percentile) in a data set, the result is L = 5 (this whole number was obtained without rounding)....
Week 2 Discussion 1 Group One – Answer each of the questions below. 1. Numeric Rating...
Week 2 Discussion 1 Group One – Answer each of the questions below. 1. Numeric Rating Scale, Wong-Baker FACES Pain Rating Scale and the Faces Pain Scale are three Pain Rating Scales. Describe each of these scales. Which scale would be appropriate for different patient populations? Do these scales provide all the information needed for a complete pain assessment? What data is missing? (CSLO 1) 2. Discuss non-pharmacologic measures used to care for patients experiencing pain. Include patient teaching that...
WEEK 10 DISCUSSION Answer the following questions. Why is a contract a special document? How is...
WEEK 10 DISCUSSION Answer the following questions. Why is a contract a special document? How is it treated differently from other documents? In your opinion, when a company elects to install an ERP system, what would be the best type of contract to use? Why?
Discussion Board Week 4 Day 1 No unread replies.No replies. A. Explain what it means to...
Discussion Board Week 4 Day 1 No unread replies.No replies. A. Explain what it means to serve as the patient’s advocate. B. Discuss the importance of advocating for the patient. C. Why is treating patients with dignity and respect important? D. Why is trust a key to preventing lawsuits? E. What may you write about your clinical assigned patient on Facebook? F. How is the HIPAA Privacy Rule different from the Security Rule?
Is the following statement true or false? Explain your answer fully. If you use terms that...
Is the following statement true or false? Explain your answer fully. If you use terms that someone who has never taken an economics course may be unfamiliar with, please define them and use them correctly. That is part of your grade. In the short run, a firm operating in a competitive industry will produce the quantity of output where price equals marginal cost as long as the price is greater than average variable cost.
Week 2 Discussion Board Answer the following question, making sure to explain your thinking in detail....
Week 2 Discussion Board Answer the following question, making sure to explain your thinking in detail. An organization estimates that 31% of new cars have a cosmetic defect, such as a scratch or a dent, when they are delivered to car dealers. This same organization believes that 6% have a functional defect – something that doesn’t work properly – and that 2% of new cars have both types of problems. If you buy a new car, what is the probability...
Also, included in the week 1 discussion-Watch the video (link below) and answer the following questions....
Also, included in the week 1 discussion-Watch the video (link below) and answer the following questions. Please make sure to to include a citation/reference page. If not included, points will be deducted. NO EXCEPTIONS. https://www.youtube.com/watch?v=3fqzVYbHanI 1. What is a common misconception of aging that you believed? 2. . What is a cultural myth about aging (either in your culture or a culture of interest to you)? 3. What is the difference between a SNF and ALF? 4. List 2 risk...
Use the following information to answer Questions 6 and 7. The 1-, 2-, 3-, and 4-year...
Use the following information to answer Questions 6 and 7. The 1-, 2-, 3-, and 4-year oil forward prices are $60, $58.35, $57.40, and $55 per barrel, respectively. Your firm is thinking about starting up an offshore drilling station and needs to forecast revenue over the next 4 years. Assume the risk-free rate is 5.25% each year and initial costs are $150,000,000. 6. (1 point) If your firm expects to extract 1,100,000 barrels of oil per year and each barrel...
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT