Module 4 Overview
February 1-7 · Reading: 11 pages · Estimated total: 6.5 hours
There is always more that could go wrong than you have money to fix. Risk management is the discipline of deciding what to fix first, and defending that decision to somebody who wants the money for something else.
This week has two halves. The first is CyBOK's treatment of risk: what it is, the elements a rating is built from, and why "eliminate the risk" is not a thing that happens. A rating is meaningless without a stated scale, so Lab 2 makes you state yours. The second is threat modeling, the systematic method for finding what could go wrong, so that you find threats by working through a checklist rather than by happening to think of them at the right moment.
Lab 2 is the first assignment where you produce a structured artifact instead of prose.
Learning Objectives
By the end of this week, the successful student will be able to:
- 2.1: Draw a data flow diagram for a described system and mark its trust boundaries.
- 2.2: Enumerate threats using STRIDE and record them in a threat table.
- 2.3: Assess the likelihood and impact of identified threats using a stated risk method.
Assignments and Tasks
Due by Sunday at 11:59 p.m. Mountain Time
- Read 4.01 Readings and Lecture Notes and work through the worked example (2 hrs 5 min)
- Read the SnapVault system description (15 min)
- 4.02 Lab 2: Threat Model a Small System (1 hr 25 min, 38 points)
No discussion this week. Read the SnapVault system description end to end before you start diagramming: the whole lab depends on facts scattered through it.
Time Estimate
| Activity | Time |
|---|---|
| Reading (11 pages) | 1 hr 30 min |
| The notes page and the worked example | 35 min |
| Reading the SnapVault description | 15 min |
| Lab 2 | 1 hr 25 min |
| Review and slack | 2 hrs 30 min |
| Total | ~6.5 hrs |