Select a security architecture approach
Unlock the complete study guide + 1,500 practice questions across 12 full exams.
Bundled into the existing Information Systems Security Architecture Professional premium course — no separate purchase.
14-day money-back guarantee — no questions asked.
Included in this chapter:
- What selecting a security architecture approach means
- Setting the scope of the architecture
- Naming the architecture type
- The TOGAF Architecture Development Method
- SABSA: business-driven security architecture
- Reusing published reference content
- Enumerating threats with STRIDE
- Scoring severity with CVSS
- Prioritizing coverage with MITRE ATT&CK
- Reading the stem: which choice is being tested
The fifth choice: what each threat-modeling framework answers
| Aspect of the choice | STRIDE | CVSS | MITRE ATT&CK |
|---|---|---|---|
| Question it answers | What can go wrong with this design? | How severe is this vulnerability? | Which adversary behaviors should we cover? |
| What it takes as input | A model of elements and data flows | One identified vulnerability | Threat intelligence about observed activity |
| What it produces | Threats per element, by category | A severity score plus its vector | Techniques mapped to tactics |
| Unit of analysis | Modeled element or data flow | Vulnerability | Adversary technique |
| Ordering of its parts | Categories are applied, not sequenced | Metric groups refine one score | Tactics are unordered goals |
| What it does not tell you | How severe or how likely any threat is | Your organizational risk | Whether your controls actually work |
Decision tree
Cheat sheet
Unlock with Premium — includes all practice exams and the complete study guide.
Also tested in
References
- The TOGAF Standard
- SABSA Executive Summary
- NIST SP 800-160 Vol. 1 Rev. 1: Engineering Trustworthy Secure Systems Whitepaper
- NIST SP 800-145: The NIST Definition of Cloud Computing Whitepaper
- NIST SP 500-292: NIST Cloud Computing Reference Architecture Whitepaper
- NIST SP 800-207: Zero Trust Architecture Whitepaper
- OWASP Threat Modeling Cheat Sheet
- OWASP Threat Modeling
- CVSS v4.0 Specification Document
- MITRE ATT&CK
- MITRE ATT&CK Enterprise Tactics