What is STRIDE in threat modeling?

D4 ยท Operations  ยท  CompTIA Security+ SY0-701
STRIDE is a threat classification model developed by Microsoft to categorize security threats during the design phase:

LetterThreatViolated Property
SSpoofingAuthentication
TTamperingIntegrity
RRepudiationNon-repudiation
IInformation DisclosureConfidentiality
DDenial of ServiceAvailability
EElevation of PrivilegeAuthorization
Memorize STRIDE and its corresponding security properties โ€” this is high-yield exam content. Each STRIDE threat has specific countermeasures: Spoofing โ†’ strong authentication, Tampering โ†’ integrity controls/HMAC, Repudiation โ†’ audit logging, Info Disclosure โ†’ encryption, DoS โ†’ rate limiting/redundancy, EoP โ†’ least privilege/access control.
โ† Back to Glossary Practice Questions โ†’