Skip to content

Module 4 Overview ​

February 1-7 · Reading: 11 pages · Estimated total: 6.5 hours

There is always more that could go wrong than you have money to fix. Risk management is the discipline of deciding what to fix first, and defending that decision to somebody who wants the money for something else.

This week has two halves. The first is CyBOK's treatment of risk: what it is, the elements a rating is built from, and why "eliminate the risk" is not a thing that happens. A rating is meaningless without a stated scale, so Lab 2 makes you state yours. The second is threat modeling, the systematic method for finding what could go wrong, so that you find threats by working through a checklist rather than by happening to think of them at the right moment.

Lab 2 is the first assignment where you produce a structured artifact instead of prose.

Learning Objectives ​

By the end of this week, the successful student will be able to:

  • 2.1: Draw a data flow diagram for a described system and mark its trust boundaries.
  • 2.2: Enumerate threats using STRIDE and record them in a threat table.
  • 2.3: Assess the likelihood and impact of identified threats using a stated risk method.

Assignments and Tasks ​

Due by Sunday at 11:59 p.m. Mountain Time ​

No discussion this week. Read the SnapVault system description end to end before you start diagramming: the whole lab depends on facts scattered through it.

Time Estimate ​

ActivityTime
Reading (11 pages)1 hr 30 min
The notes page and the worked example35 min
Reading the SnapVault description15 min
Lab 21 hr 25 min
Review and slack2 hrs 30 min
Total~6.5 hrs

Released under the MIT License.