PASTA Threat Model
Jump to:
Overview
The PASTA (Process for Attack Simulation and Threat Analysis) threat model is a risk-centric framework designed to identify, analyze, and mitigate cyber threats through a structured, attacker-focused approach. It helps organizations align security efforts with business objectives by simulating attack scenarios to prioritize risks and defenses effectively.
Primary Objectives
- Enable consistent identification and prioritization of threats based on business impact and attacker behavior
- Benefit security architects, risk managers, developers, and executives by providing actionable threat intelligence
- Support informed decision-making and accountability by linking threat analysis to risk management and mitigation strategies
Scope & Applicability
- Applicable across industries with complex applications and systems, including finance, healthcare, and critical infrastructure
- Covers threat modeling for application security, infrastructure, and business processes; excludes physical security and purely compliance-driven controls
- Requires established asset inventories, business process documentation, and governance frameworks as preconditions
Core Structure
- Comprises seven stages: Definition of Objectives, Definition of Technical Scope, Application Decomposition, Threat Analysis, Vulnerability Analysis, Attack Modeling & Simulation, and Risk Analysis & Management
- Organized to progress from business and technical context to detailed attack simulation and risk prioritization
- Utilizes terminology such as threat agents, attack vectors, vulnerabilities, and risk scenarios to map threats to business impact
How It Is Used
- Typically adopted through phased rollouts starting with critical applications or business units
- Assessment workflows include iterative threat identification, simulation of attack paths, and risk scoring to guide remediation
- Integrated into engineering processes via security design reviews, threat-informed development, and continuous risk assessment during SDLC
Implementation Artifacts
- Derived policies and procedures focus on threat identification, risk assessment, and mitigation planning
- Control libraries often mapped to standards like NIST SP 800-53 or ISO/IEC 27001 for comprehensive coverage
- Evidence artifacts include threat models, attack trees, simulation reports, and risk treatment plans
Measurement & Maturity
- Key metrics include number of identified threats, risk reduction over time, and coverage of critical assets
- Maturity assessed through capability levels reflecting integration depth, automation, and continuous improvement
- Common baselines range from initial threat awareness to advanced, automated attack simulation and dynamic risk management
Common Pitfalls
- Focusing on checklist completion rather than understanding attacker motivations and business impact
- Overly broad scope leading to resource dilution or overly narrow scope missing critical threats
- Lack of ownership for threat models and outdated or incomplete documentation reducing effectiveness
Integration & Mapping
- Maps effectively to frameworks such as STRIDE, MITRE ATT&CK, and risk management standards like NIST RMF
- Integrates with governance, risk, and compliance (GRC) platforms, security operations centers (SOC), incident response (IR), and software development lifecycle (SDLC) processes
- Tooling includes threat modeling software, attack simulation platforms, and automated risk assessment tools
When Not to Use It
- May be too resource-intensive for small organizations or projects with limited security maturity
- Less suitable when rapid, lightweight threat assessments are needed or when regulatory compliance is the sole driver
- Consider simpler models or staged approaches for initial threat awareness before adopting full PASTA methodology
Standards & References
- Primary reference: PASTA methodology documentation by Tony UcedaVélez and Marco M. Morana
- Companion materials include implementation guides, case studies, and mappings to NIST and ISO standards
More in Threat Models