Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Data Security @ the personal level

Data Security @ the personal level

personal security briefing to employees (e.g for ISO 27001 compliance)

Arnon Rotem-Gal-Oz

April 20, 2017
Tweet

More Decks by Arnon Rotem-Gal-Oz

Other Decks in Technology

Transcript

  1. Formal threat analysis 
 The STRIDE model 
 
 


    Also see • OWASP https://www.owasp.org/ • https://www.owasp.org/index.php/Threat_Risk_Modeling#STRIDE • Common Criteria https://www.commoncriteriaportal.org/
  2. Spoofing (of user identity) 
 Tampering 
 Repudiation 
 Information

    disclosure 
 Denial of service 
 Elevation of privilege