Skip to content
Security / Governance, Risk & Compliance

Hazard modeling and risk analysis based on STRIDE and qualitative risk analysis

The training course Threat Modeling and Risk Analysis Based on STRIDE and Qualitative Risk Analysis is an intensive one-day course designed for IT and cyber security professionals. Participants will explore advanced techniques for identifying potential threats in IT systems and learn how to effectively assess the associated risks.

Issues

The training covers the following key topics:

  • Foundations of threat modeling and its role in the security lifecycle of IT systems.

  • A detailed analysis of STRIDE’s six threat categories: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.

  • Techniques for creating and analyzing data flow diagrams (DFDs) in a security context.

  • Qualitative risk analysis methodology, including the creation and interpretation of risk matrices.

  • Risk management strategies: avoidance, transfer, reduction and acceptance.

  • Practical methods for combining threat modeling with risk analysis for effective system security.

  • Techniques for prioritizing risks and allocating resources based on risk analysis results.

  • Develop effective mitigation plans for identified risks.

  • Best practices for documenting and communicating the results of hazard modeling and risk analysis.

Benefits

  • In-depth understanding of the STRIDE methodology and its practical application in threat modeling.
  • Ability to create comprehensive threat models for IT systems to better secure IT infrastructure.
  • Ability to perform qualitative risk analysis to effectively prioritize risks and allocate resources.
  • Practical experience in creating data flow diagrams (DFDs) and their use in the threat modeling process.
  • Knowledge of risk management strategies and ability to develop effective risk mitigation plans.
  • The ability to immediately apply the knowledge gained in daily work, which will contribute to the security of IT systems in the organization.
  • Networking with other industry professionals and sharing experiences.

Who is this training for?

IT systems architects
Safety engineers
Risk analysts
Security auditors
IT project managers
Compliance specialists
Developers interested in application security
Cyber security consultants

Prerequisites

  • Basic knowledge of IT security and software development life cycle (SDLC).
  • General understanding of concepts related to cyber security, such as confidentiality, integrity and availability of data.
  • Knowledge of basic concepts related to IT systems architecture.
  • Experience working with information systems or IT projects (welcome but not required).
  • Openness to learning and willingness to actively participate in practical exercises.

Training program

01

Introduction to Threat Modeling

  • STRIDE methodology
  • Threat Modeling Process Using STRIDE
  • Introduction to Risk Analysis
  • Application of Risk Analysis to Hazard Modeling
  • Risk Management Strategies and Mitigation
  • Summary and Q&A Session
  • Completion of Training

Delivery Methods

Online

  • Convenience of participating from anywhere
  • Interactive live sessions with trainer
  • Materials available for 30 days
  • No travel costs

On-site

  • Direct contact with trainer and group
  • Intensive hands-on workshops
  • Networking with other participants
  • Full focus on learning

Frequently asked questions

What are the prerequisites for this training?

For Hazard modeling and risk analysis based on STRIDE and qualitative risk analysis we recommend: Basic knowledge of IT security and software development life cycle (SDLC).; General understanding of concepts related to cyber security, such as confidentiality, integrity and availability of data.; Knowledge of basic concepts related to IT systems architecture..

What is the format and duration of this training?

The training lasts 1 day and is available in online and on-site format. Sessions run from 9:00 AM to 4:00 PM. We can also customize the schedule to fit your team's needs.

Who is this training designed for?

This training is designed for: IT systems architects; Safety engineers; Risk analysts.

Patrycja Petkowska
Patrycja Petkowska Opiekun szkolenia

Request a quote

Funding Options

Check funding options for your company

Up to 80%

Development Services Database

Up to 80% funding for SMEs from EU funds

Check availability
Up to 100%

National Training Fund

Up to 100% funding for employers

Learn more

Trusted by

We train teams at Poland's largest companies

ING Bank - EITT client
mBank - EITT client
PKO Bank Polski - EITT client
PZU - EITT client
Allianz - EITT client
T-Mobile - EITT client
KGHM - EITT client
PGE - EITT client
IKEA - EITT client
InPost - EITT client
Leroy Merlin - EITT client
ZUS - EITT client

Interested in this training?

Contact us - we'll prepare an offer tailored to your organization's needs.

500+ experts
2500+ trainings available
ISO 9001 quality certified
Request Training
Call us +48 22 487 84 90