From the course: Security Architecture: A Strategic Approach by Infosec

Unlock this course with a free trial

Join today to access over 25,300 courses taught by industry experts.

Threat modeling and security architecture

Threat modeling and security architecture

- [Instructor] Before we explain the relationship between threat modeling and security architecture, I want to go back and recall the role of the security architect in an enterprise. The role of the security architect is to, first and foremost, understand business requirements. Second, to translate those business requirements into security requirements. And third, to design practical and effective security controls that will adequately address the security requirements, and in turn, facilitate and support business goals. So in order to design practical and effective security controls, you need to understand what it is that those controls will be protecting against. And this is where threat modeling comes into play. By incorporating a threat modeling methodology into the security architecture and design process, the security architects will be able to consistently understand security requirements. I said this many times before because I think it's very important to understand…

Contents