Glossary · ISO/SAE 21434
Threat Scenario
Plausible way an attacker can compromise a cybersecurity property of an asset.
Glossary · ISO/SAE 21434
Plausible way an attacker can compromise a cybersecurity property of an asset.
A threat scenario describes how an attacker compromises an asset's cybersecurity property — typically expressed using STRIDE-style categories (Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege). It is the bridge between damage scenarios and attack paths.
Related terms
Description of the harm that occurs when a cybersecurity property of an asset is compromised.
Sequence of attacker steps from initial access to compromise of a cybersecurity property.
Threat Analysis and Risk Assessment — the structured cybersecurity risk method of ISO/SAE 21434.
Related pages
Need help applying Threat Scenario on a programme? Use the contact form or request a KAVACH demo.