Cyber Threat Modeling: Survey, Assessment, and Representative Framework

By Deborah Bodeau , Catherine McCollum , David Fox

This report, part of the Next Generation Cyber Infrastructure Apex program, presents a comparative assessment of the surveyed frameworks, and extends an existing framework to serve as a basis for cyber threat modeling for a variety of purposes.

Download Resources

This report provides a survey of cyber threat modeling frameworks, presents a comparative assessment of the surveyed frameworks, and extends an existing framework to serve as a basis for cyber threat modeling for a variety of purposes. This paper also presents a threat modeling framework for the NGCI Apex program, with initial population of that framework. The survey, assessment, and framework as initially populated are general enough to be used by medium-to-large organizations in critical infrastructure sectors, particularly in the FSS, seeking to ensure that cybersecurity and resilience efforts consider cyber threats in a rigorous, repeatable way.

Note: This report is part of a larger suite of publications supporting the Next Generation Cyber Infrastructure Apex program.