
Step 4. Identify Mitigation Techniques and Technologies
After you identify which threats you will fix, you must determine the available mitigation techniques for each threat, and the most appropriate technology to reduce the effect of each threat.
For example, depending on the details of your target environment, you can reduce the effect of data-tamper threats by using authorization techniques. You then have to determine the appropriate authorization technology to use (for example, discretionary access control lists (DACLs), permissions, or IP restrictions).
Important |
|---|
|
When you evaluate mitigation techniques and technologies to use, you must consider what makes business sense for your company, and any policies your company has that might affect the mitigation technique to choose. |
After you complete the TMA, do the following:
-
Document the security model and deployment considerations
-
Implement and test mitigations
-
Keep the threat model synchronized with design