Vulnerability Management, Threat Modeling (STRIDE), and CVSS

Securing modern distributed systems requires proactive Threat Modeling during the architectural design phase, combined with automated Continuous Vulnerability Management throughout the operational lifecycle.


⚡ Quick Dive

The STRIDE Threat Modeling Framework

Threat Category Property Violated Definition Mitigation Technique
S - Spoofing Authenticity Pretending to be an authorized user or system Strong authentication, mTLS, digital signatures
T - Tampering Integrity Unauthorized modification of data or code Cryptographic hashes, HMACs, immutable storage
R - Repudiation Non-Repudiability Denying having performed an action Immutable audit logs, WORM storage, SIEM
I - Information Disclosure Confidentiality Exposing sensitive data to unauthorized parties Encryption-at-rest/in-transit, least privilege
D - Denial of Service Availability Preventing legitimate users from accessing service Rate limiting, autoscaling, CDN edge caching
E - Elevation of Privilege Authorization Gaining higher access levels than permitted RBAC, boundary checks, non-root containers

📖 Extended Guide

1. CVSS Scoring & Remediation SLAs

The Common Vulnerability Scoring System (CVSS v3.1 / v4.0) standardizes severity ratings ($0.0$ to $10.0$):

CVSS Score Range Severity Rating Standard Production Remediation SLA
9.0 - 10.0 CRITICAL < 24 to 48 Hours (Immediate Hotfix)
7.0 - 8.9 HIGH < 7 to 14 Days
4.0 - 6.9 MEDIUM < 30 Days (Next sprint release)
0.1 - 3.9 LOW < 90 Days / Backlog