STRIDE helps teams identify and analyze potential security threats in software systems. The method addresses various threat types such as Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Executable approach: can be applied and produces an outcome.
What organizes, connects, or makes decisions possible.
STRIDE is a software threat-modeling framework that systematically checks six common threat classes: spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege.
Microsoft developed STRIDE in the late 1990s as a reasoning framework for software threat modeling. Its name combines six recurring security properties that guide questions about system elements and data flows.
View the system as data flows crossing trusted and less-trusted boundaries. For each element, ask whether someone could spoof an identity, tamper with data, repudiate an action, disclose information, deny a service, or elevate privileges. Then assess the findings and connect them to mitigations.
Six categories provide recurring security questions for an analysis.
Data flows across trust boundaries show where threats may arise.
Identified threats are addressed with technical or organizational measures.
STRIDE helps development teams structure security risks early and traceably. It provides a complete question set, but it does not assess risk automatically and does not replace domain expertise, testing, or security architecture.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.