Skip to main content
STRIDE model

STRIDE model

Search complete. 26 mentions across 5 episodes found for "STRIDE model".

Sep 15, 2026

speaker_0NARRATOR
0:21
If one layer fails, another still protects the asset.
speaker_0NARRATOR
0:24
The CIA triad, confidentiality, integrity, availability defines what you are protecting while STRIDE, spoofing, tampering, repudiation, information disclosure, denial-of-service, elevation of privilege helps you enumerate what can go wrong at each element of a data flow diagram, DFD.
speaker_0NARRATOR
0:43
A useful mental model, picture a file upload as a hostile input crossing a trust boundary.
speaker_0NARRATOR
0:48
Everything before validation is untrusted.
speaker_0NARRATOR
2:09
Identify external entities, processes, data stores, and critically, the trust boundaries.
speaker_0NARRATOR
2:15
Reuse the DFD conventions from your earlier work so your diagram is readable and consistent.
speaker_0NARRATOR
2:20
Step two, for each element and each data flow, run STRIDE and list at least one credible threat per relevant category.
speaker_0NARRATOR
2:26
Do not force categories that make no sense, but justify every omission in one sentence.
speaker_0NARRATOR
0:00
Theoretical recap.
speaker_0NARRATOR
0:01
STRIDE is a threat modeling framework that classifies threats into six categories.
speaker_0NARRATOR
0:06
Spoofing, impersonating an identity, tampering, altering data or code, repudiation, denying an action without traceability, information disclosure, exposing data to unauthorized parties, denial of service, making a resource unavailable, and elevation of privilege, gaining rights beyond what was granted.
speaker_0NARRATOR
0:24
The mental model is simple.
speaker_0NARRATOR
0:26
For each element of your system, data flows, processes, data stores, external entities, you ask how could an attacker spoof, tamper, repudiate, disclose, DoS, or elevate here? Each STRIDE category maps closely to a CIA property.
speaker_0NARRATOR
0:41
Spoofing/EOP relate to authentication and authorization, tampering to integrity, information disclosure to confidentiality, DoS to availability, and repudiation to non-repudiation/auditing.
speaker_0NARRATOR
0:54
A common mistake is to list generic threats without tying them to a concrete data flow or trust boundary.
speaker_0NARRATOR
1:22
The mitigation is deriving author_id from the authenticated session token server side.
speaker_0NARRATOR
0:19
Stride builds directly on that foundation.
speaker_0NARRATOR
0:21
It gives you a checklist of six threat categories to apply to each component of your system so that you do not forget an entire class of attacks.
speaker_0NARRATOR
0:28
STRIDE is an acronym.
speaker_0NARRATOR
0:30
Each letter is the initial of one threat category.
speaker_0NARRATOR
0:32
The six categories are spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege.
speaker_0HOST
8:14
Right.
speaker_1HOST
8:15
The guide actually recommends applying the stride threat modeling methodology to these pipelines.
speaker_0HOST
8:19
OK, let's pause on STRIDE because we shouldn't assume everyone has that acronym memorized.
speaker_1HOST
8:24
Fair enough.
speaker_1HOST
8:24
STRIDE stands for spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege.
speaker_1HOST
8:32
It's an old school Microsoft framework.
speaker_0HOST
8:34
Yeah, I remember that from standard IT.
Sean GerberHOST
1:44
The training block is gonna be getting into one point one zero.
Sean GerberHOST
1:47
This is threat modeling concepts, methodologies, STRIDE, PASTA, DREAD, attack trees, and trust boundaries.
Sean GerberHOST
1:53
All of these are gonna be parts that are gonna be tested on the ISC squared CISSP exam.
Sean GerberHOST
1:58
And then the th-- we're gonna have three CISSP questions that are gonna specifically be calling out these aspects.

18 MINS LATER

Sean GerberHOST
19:46
Have an Iron Man doing his funny thing with all the holograms.
Sean GerberHOST
19:49
Same concept.
Sean GerberHOST
19:51
This is where STRIDE, S-T-R-I-D-E, lives.
Sean GerberHOST
19:55
Best coverage during design requires real architectural detail to be worth anything.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.