Vulnerability Management, Threat Modeling (STRIDE), and CVSS
Securing modern distributed systems requires proactive Threat Modeling during the architectural design phase, combined with automated Continuous Vulnerability Management throughout the operational lifecycle.
⚡ Quick Dive
The STRIDE Threat Modeling Framework
| Threat Category | Property Violated | Definition | Mitigation Technique |
|---|---|---|---|
| S - Spoofing | Authenticity | Pretending to be an authorized user or system | Strong authentication, mTLS, digital signatures |
| T - Tampering | Integrity | Unauthorized modification of data or code | Cryptographic hashes, HMACs, immutable storage |
| R - Repudiation | Non-Repudiability | Denying having performed an action | Immutable audit logs, WORM storage, SIEM |
| I - Information Disclosure | Confidentiality | Exposing sensitive data to unauthorized parties | Encryption-at-rest/in-transit, least privilege |
| D - Denial of Service | Availability | Preventing legitimate users from accessing service | Rate limiting, autoscaling, CDN edge caching |
| E - Elevation of Privilege | Authorization | Gaining higher access levels than permitted | RBAC, boundary checks, non-root containers |
📖 Extended Guide
1. CVSS Scoring & Remediation SLAs
The Common Vulnerability Scoring System (CVSS v3.1 / v4.0) standardizes severity ratings ($0.0$ to $10.0$):
| CVSS Score Range | Severity Rating | Standard Production Remediation SLA |
|---|---|---|
| 9.0 - 10.0 | CRITICAL | ⚡ < 24 to 48 Hours (Immediate Hotfix) |
| 7.0 - 8.9 | HIGH | < 7 to 14 Days |
| 4.0 - 6.9 | MEDIUM | < 30 Days (Next sprint release) |
| 0.1 - 3.9 | LOW | < 90 Days / Backlog |