A threat-classification checklist from Microsoft's Security Development Lifecycle: spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege 1. For an AI system it is walked per element of the data-flow diagram and then extended with AI-specific catalogues such as MITRE ATLAS and the OWASP lists.
- Developed in
- ch. 15, Threat modelling the deployed system
ch. 05, Pattern: AI Threat Model - Chapters
- ch. 05, Patterns · ch. 06, The Role · ch. 15, Deployment
- Contrast with
- ATLAS
- Source
- 1 numbered reference, listed below
Where it is used
3 chapters of the Body of Knowledge use the term. Each link opens the first section that does.
- 05 · Patterns Pattern: AI Threat Model 1 mention
- 06 · The Role Skills, by workflow 1 mention
- 15 · Deployment Periodic assurance 1 mention
Related terms
Sources
- [1] Threats: Microsoft Threat Modeling Tool (the STRIDE model: spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege; the tool is a core element of the Security Development Lifecycle). Microsoft Learn. 2017-08-17. https://learn.microsoft.com/en-us/azure/security/develop/threat-modeling-tool-threats (verified: primary)
Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .