10/07/2025

During a technical cybersecurity review, it is not unlikely that someone missed something; a vulnerability that is overlooked in their object of analysis. Without a proper process with purposeful methods, it would be very difficult to minimize the number of mistakes made. This is where threat modeling and the OCTAVE method can come into play during a technical security review.

What is Threat Modeling?

Threat modeling is a process of creating a model around the object of analysis, specifying its operating components, to identify and understand possible attack vectors while categorizing the risk found by their impact, likelihood, recreation, and mitigation difficulty. After understanding all the risks found, the technical team can move on to create countermeasures, starting with the most potent and repeatable vulnerability exploits.

One of the most important factors of threat modeling is knowing the general structure of the target through data flow diagrams (DFD) to understand how each operating component connects with each other and the data flows through them. Using a DFD of a web application in Figure 1 as an example, it is possible to see which component acts as a bridge between the user and the database server, along with the types of data being transmitted. 

TMA Solutions
Figure 1 – DFD of a web application. 

Currently, there are many different methods and standards used for threat modeling. Noteworthy and popular names include STRIDE, DREAD, and OCTAVE. STRIDE is the most well-known standard used to help categorize the threats found within a system. Accompanying STRIDE is DREAD, which is used to score those threats by their damage, repeatability, severity, and more. STRIDE has been known to be less used as a threat modeling method and is created with a pure security view, which might hinder business operations and desired functions. While DREAD is considered to be outdated, as well as inconsistent with their scoring. These flaws led to the creation of OCTAVE. 

What is the OCTAVE method?

OCTAVE is an acronym for Operationally Critical Threat, Asset, and Vulnerability Evaluation. Its development was primed due to the need for organizational priorities to be included along with technological requirements during technical assessments. At the time, the developers considered other threat modeling approaches uncomprehensive and lacking organizational involvement. OCTAVE was also developed with strategic issues in mind rather than tactical, meaning it attempts to have an overview of a significantly longer time frame. Other methods were also created to be used solely by outside experts. This method allows for self-direction for the organization to make its evaluations to be later used in security decisions. 

OCTAVE categorizes its three main elements of concern into the following:

  • Threat: they are potential actions that could exploit vulnerabilities and harm assets.

    • Internal threat: threats coming from inside the organization, be it intentional or not.

    • External threat: threats coming from outside the organization.

  • Assets: resources that hold value to the organization and require protection.

    • Informational: includes objects like sensitive data and confidential documentation.

    • Infrastructure: physical devices and equipment that form the organization’s IT operations.

    • Human: employees within the company who may protect or damage the system.

    • Critical: most important assets among the previously identified assets.

  • Vulnerabilities: generally, technological weaknesses within the operational systems.

    • Organizational: vulnerability that exists outside of technologies and inside the organizational structure itself.

    • Technological: vulnerability in either the hardware property or software configuration of a device or system.

The threat modeling phases of OCTAVE are as follows:

  • Phase 1: Build Asset-Based Threat Profiles. Using staff knowledge from multiple organizational levels along with a standard information catalog of threats and practices, the analysis team can categorize and discover assets, threats, and security requirements of the organization.

  • Phase 2: Identify Infrastructure Vulnerabilities. Rechanneling the information created after the first phase into this phase to be combined with infrastructure components to result in the understanding of which are high-priority components, existing misconfigurations, malpractices, and vulnerabilities.

  • Phase 3: Develop Security Strategy and Plans. This is where the organization uses the previously organized information to decide its next course of action. Addressing risks with mitigation plans and coming up with protection strategies are all part of this phase.

TMA Solutions
Figure 2 – The OCTAVE Process Diagram

What is the OCTAVE Criteria?

The OCTAVE Criteria is a set of outputs and principles followed by their attributes. It was created as a standard to guide the evaluation process and for the organization to understand the results. It contains requirements needed to make OCTAVE, or other methods that follow this criteria, a self-directed method of threat modeling.

The three main categories of the OCTAVE Criteria are as follows:

  • Principle: It is the fundamental basis and purpose of an evaluation.

  • Attribute: it is a distinctive characteristic that works as a requirement and an evaluation’s success indicator.

  • Output: it works as an objective or result requirement of each evaluation phase to help the team understand what their analysis must achieve during them. 

TMA Solutions
Figure 3 – One of the Principles & its Set of Attributes from the OCTAVE Criteria
TMA Solutions
Figure 4 – OCTAVE Outputs Requirement of Each OCTAVE Phase

Case Study

Willow Creek University was looking to deploy a web application called MediaWiki on their intranet to help regulate information about their various newly built and existing facilities, as well as past events they have hosted at those locations. During their security analysis process, they opted to use the OCTAVE method for threat modeling to understand critical assets and how they could be vulnerable.  

Deriving from the Level 1 DFD (Figure 1), a more detailed DFD Level can be drawn to specify types of data flows that may occur during the web application’s usage. One type of request that both a normal user and the administrator can make is query-type requests. Through MediaWiki’s documentation, the development team can figure out which application features send these types of requests and draw an appropriate DFD Level 2 (Figure 5). 

TMA Solutions
Figure 5 – DFD detailing query-type requests inside MediaWiki 

Using that DFD Level 2 as a base, the security team is able to pinpoint threats that may happen due to that specific request. After listing all the threats that they are aware of, they can rank the threats by their risk severity and repeatability. A general description of the threat is also given to help Willow Creek University’s non-technical teams to further involved in the threat modeling process. Figure 6 provides the first three table entries of the threats found based on DFD Level 2 – Query-type Requests (Figure 5). 

TMA Solutions
Figure 6 – Some of the table entries containing threats of each request type 

Once the risks are listed, the security team can use their knowledge along with open-source information to come up with a mitigation strategy appropriate to the threat listed. The ID numbers are used to help connect the threat table and the mitigation strategy table. This can be seen using Figure 7, where the threat name column is used to further connect with the threat table in Figure 6. 

TMA Solutions
Figure 7 – Some of the table entries containing each threat’s appropriate mitigation strategy 

The OCTAVE report produced as a result of the process allowed Willow Creek University’s development team to have a detailed understanding of the organization's priorities, existing threats, and appropriate countermeasures. It led to a successful and secure deployment of MediaWiki while being operational to the specific needs of the university. 

Conclusion

Threat modeling is an essential part of a technical cybersecurity review. It helps remove the chances of overlooking vulnerabilities and risks. The OCTAVE method introduces step-by-step instructions to be deployed on a full scale, as well as incorporates organizational needs into security analysis. The OCTAVE Criteria provides expected results and works as a success confirmation. Not using the OCTAVE method could lead to lackluster or unsuccessful threat modeling, and without threat modeling in general, it is likely impossible to know if the object of analysis is secure. 

TMA Solutions
Author: TMA Solutions
Table Of Content
What is Threat Modeling?
What is the OCTAVE method?
What is the OCTAVE Criteria?
Case Study
Conclusion
Start your project today!
Contact Us
Start your project today!
Contact Us
decor

Contact Us

Share with us your challenges. We are here to support.

Name *
Email *
Company *
Websites
Country *
United States
AndorraAndorra
United Arab EmiratesUnited Arab Emirates
AfghanistanAfghanistan
Antigua and BarbudaAntigua and Barbuda
AnguillaAnguilla
AlbaniaAlbania
ArmeniaArmenia
AngolaAngola
ArgentinaArgentina
AustriaAustria
AustraliaAustralia
ArubaAruba
Åland IslandsÅland Islands
AzerbaijanAzerbaijan
Bosnia and HerzegovinaBosnia and Herzegovina
BarbadosBarbados
BangladeshBangladesh
BelgiumBelgium
Burkina FasoBurkina Faso
BulgariaBulgaria
BahrainBahrain
BurundiBurundi
BeninBenin
BermudaBermuda
Brunei DarussalamBrunei Darussalam
BoliviaBolivia
BrazilBrazil
BahamasBahamas
BhutanBhutan
BotswanaBotswana
BelarusBelarus
BelizeBelize
CanadaCanada
Congo, Democratic Republic of theCongo, Democratic Republic of the
Central African RepublicCentral African Republic
CongoCongo
SwitzerlandSwitzerland
Cote d'IvoireCote d'Ivoire
ChileChile
CameroonCameroon
ChinaChina
ColombiaColombia
Costa RicaCosta Rica
CubaCuba
Cape VerdeCape Verde
CyprusCyprus
Czech RepublicCzech Republic
GermanyGermany
DjiboutiDjibouti
DenmarkDenmark
DominicaDominica
Dominican RepublicDominican Republic
AlgeriaAlgeria
EcuadorEcuador
EstoniaEstonia
EgyptEgypt
EritreaEritrea
SpainSpain
EthiopiaEthiopia
FinlandFinland
FijiFiji
Falkland IslandsFalkland Islands
Federated States of MicronesiaFederated States of Micronesia
FranceFrance
GabonGabon
United KingdomUnited Kingdom
GrenadaGrenada
GeorgiaGeorgia
GuernseyGuernsey
GhanaGhana
GibraltarGibraltar
GambiaGambia
GuineaGuinea
Equatorial GuineaEquatorial Guinea
GreeceGreece
GuatemalaGuatemala
Guinea-BissauGuinea-Bissau
GuyanaGuyana
Hong KongHong Kong
HondurasHonduras
CroatiaCroatia
HaitiHaiti
HungaryHungary
IndonesiaIndonesia
IrelandIreland
IsraelIsrael
Isle of ManIsle of Man
IndiaIndia
IraqIraq
IranIran
IcelandIceland
ItalyItaly
JerseyJersey
JamaicaJamaica
JordanJordan
JapanJapan
KenyaKenya
KyrgyzstanKyrgyzstan
CambodiaCambodia
ComorosComoros
Saint Kitts and NevisSaint Kitts and Nevis
North KoreaNorth Korea
South KoreaSouth Korea
KuwaitKuwait
Cayman IslandsCayman Islands
KazakhstanKazakhstan
LaosLaos
LebanonLebanon
Saint LuciaSaint Lucia
LiechtensteinLiechtenstein
Sri LankaSri Lanka
LiberiaLiberia
LesothoLesotho
LithuaniaLithuania
LuxembourgLuxembourg
LatviaLatvia
LibyaLibya
MoroccoMorocco
MonacoMonaco
MoldovaMoldova
MontenegroMontenegro
MadagascarMadagascar
North MacedoniaNorth Macedonia
MaliMali
BurmaBurma
MongoliaMongolia
MacaoMacao
MauritaniaMauritania
MontserratMontserrat
MaltaMalta
MauritiusMauritius
MaldivesMaldives
MalawiMalawi
MexicoMexico
MalaysiaMalaysia
MozambiqueMozambique
NamibiaNamibia
NigerNiger
NigeriaNigeria
NicaraguaNicaragua
NetherlandsNetherlands
NepalNepal
New ZealandNew Zealand
OmanOman
PanamaPanama
PeruPeru
French PolynesiaFrench Polynesia
Papua New GuineaPapua New Guinea
PhilippinesPhilippines
PakistanPakistan
PolandPoland
Puerto RicoPuerto Rico
PortugalPortugal
PalauPalau
ParaguayParaguay
QatarQatar
RomaniaRomania
SerbiaSerbia
RussiaRussia
RwandaRwanda
Saudi ArabiaSaudi Arabia
Solomon IslandsSolomon Islands
SeychellesSeychelles
SudanSudan
SwedenSweden
SingaporeSingapore
SloveniaSlovenia
SlovakiaSlovakia
Sierra LeoneSierra Leone
San MarinoSan Marino
SenegalSenegal
SomaliaSomalia
SurinameSuriname
Sao Tome and PrincipeSao Tome and Principe
El SalvadorEl Salvador
SyriaSyria
SwazilandSwaziland
Turks and Caicos IslandsTurks and Caicos Islands
ChadChad
TogoTogo
ThailandThailand
TajikistanTajikistan
Timor-LesteTimor-Leste
TurkmenistanTurkmenistan
TunisiaTunisia
TongaTonga
TurkeyTurkey
Trinidad and TobagoTrinidad and Tobago
TaiwanTaiwan
TanzaniaTanzania
UkraineUkraine
UgandaUganda
United StatesUnited States
UruguayUruguay
UzbekistanUzbekistan
Saint Vincent and the GrenadinesSaint Vincent and the Grenadines
VenezuelaVenezuela
Virgin Islands, BritishVirgin Islands, British
VietnamVietnam
VanuatuVanuatu
SamoaSamoa
YemenYemen
South AfricaSouth Africa
ZambiaZambia
ZimbabweZimbabwe
Phone
(+1)

Andorra Andorra(+376)
United Arab Emirates United Arab Emirates(+971)
Afghanistan Afghanistan(+93)
Antigua and Barbuda Antigua and Barbuda(+1 268)
Anguilla Anguilla(+1 264)
Albania Albania(+355)
Armenia Armenia(+374)
Angola Angola(+244)
Argentina Argentina(+54)
Austria Austria(+43)
Australia Australia(+61)
Aruba Aruba(+297)
Åland Islands Åland Islands(+358)
Azerbaijan Azerbaijan(+994)
Bosnia and Herzegovina Bosnia and Herzegovina(+387)
Barbados Barbados(+1 246)
Bangladesh Bangladesh(+880)
Belgium Belgium(+32)
Burkina Faso Burkina Faso(+226)
Bulgaria Bulgaria(+359)
Bahrain Bahrain(+973)
Burundi Burundi(+257)
Benin Benin(+229)
Bermuda Bermuda(+1 441)
Brunei Darussalam Brunei Darussalam(+673)
Bolivia Bolivia(+591)
Brazil Brazil(+55)
Bahamas Bahamas(+1 242)
Bhutan Bhutan(+975)
Botswana Botswana(+267)
Belarus Belarus(+375)
Belize Belize(+501)
Canada Canada(+1)
Congo, Democratic Republic of the Congo, Democratic Republic of the(+243)
Central African Republic Central African Republic(+236)
Congo Congo(+242)
Switzerland Switzerland(+41)
Cote d'Ivoire Cote d'Ivoire(+225)
Chile Chile(+56)
Cameroon Cameroon(+237)
China China(+86)
Colombia Colombia(+57)
Costa Rica Costa Rica(+506)
Cuba Cuba(+53)
Cape Verde Cape Verde(+238)
Cyprus Cyprus(+357)
Czech Republic Czech Republic(+420)
Germany Germany(+49)
Djibouti Djibouti(+253)
Denmark Denmark(+45)
Dominica Dominica(+1 767)
Dominican Republic Dominican Republic(+1 809)
Algeria Algeria(+213)
Ecuador Ecuador(+593)
Estonia Estonia(+372)
Egypt Egypt(+20)
Eritrea Eritrea(+291)
Spain Spain(+34)
Ethiopia Ethiopia(+251)
Finland Finland(+358)
Fiji Fiji(+679)
Falkland Islands Falkland Islands(+500)
Federated States of Micronesia Federated States of Micronesia(+691)
France France(+33)
Gabon Gabon(+241)
United Kingdom United Kingdom(+44)
Grenada Grenada(+1 473)
Georgia Georgia(+995)
Guernsey Guernsey(+44)
Ghana Ghana(+233)
Gibraltar Gibraltar(+350)
Gambia Gambia(+220)
Guinea Guinea(+224)
Equatorial Guinea Equatorial Guinea(+240)
Greece Greece(+30)
Guatemala Guatemala(+502)
Guinea-Bissau Guinea-Bissau(+245)
Guyana Guyana(+592)
Hong Kong Hong Kong(+852)
Honduras Honduras(+504)
Croatia Croatia(+385)
Haiti Haiti(+509)
Hungary Hungary(+36)
Indonesia Indonesia(+62)
Ireland Ireland(+353)
Israel Israel(+972)
Isle of Man Isle of Man(+44)
India India(+91)
Iraq Iraq(+964)
Iran Iran(+98)
Iceland Iceland(+354)
Italy Italy(+39)
Jersey Jersey(+44)
Jamaica Jamaica(+1 876)
Jordan Jordan(+962)
Japan Japan(+81)
Kenya Kenya(+254)
Kyrgyzstan Kyrgyzstan(+996)
Cambodia Cambodia(+855)
Comoros Comoros(+269)
Saint Kitts and Nevis Saint Kitts and Nevis(+1 869)
North Korea North Korea(+850)
South Korea South Korea(+82)
Kuwait Kuwait(+965)
Cayman Islands Cayman Islands(+1 345)
Kazakhstan Kazakhstan(+7)
Laos Laos(+856)
Lebanon Lebanon(+961)
Saint Lucia Saint Lucia(+1 758)
Liechtenstein Liechtenstein(+423)
Sri Lanka Sri Lanka(+94)
Liberia Liberia(+231)
Lesotho Lesotho(+266)
Lithuania Lithuania(+370)
Luxembourg Luxembourg(+352)
Latvia Latvia(+371)
Libya Libya(+218)
Morocco Morocco(+212)
Monaco Monaco(+377)
Moldova Moldova(+373)
Montenegro Montenegro(+382)
Madagascar Madagascar(+261)
North Macedonia North Macedonia(+389)
Mali Mali(+223)
Burma Burma(+95)
Mongolia Mongolia(+976)
Macao Macao(+853)
Mauritania Mauritania(+222)
Montserrat Montserrat(+1 664)
Malta Malta(+356)
Mauritius Mauritius(+230)
Maldives Maldives(+960)
Malawi Malawi(+265)
Mexico Mexico(+52)
Malaysia Malaysia(+60)
Mozambique Mozambique(+258)
Namibia Namibia(+264)
Niger Niger(+227)
Nigeria Nigeria(+234)
Nicaragua Nicaragua(+505)
Netherlands Netherlands(+31)
Nepal Nepal(+977)
New Zealand New Zealand(+64)
Oman Oman(+968)
Panama Panama(+507)
Peru Peru(+51)
French Polynesia French Polynesia(+689)
Papua New Guinea Papua New Guinea(+675)
Philippines Philippines(+63)
Pakistan Pakistan(+92)
Poland Poland(+48)
Puerto Rico Puerto Rico(+1 787)
Portugal Portugal(+351)
Palau Palau(+680)
Paraguay Paraguay(+595)
Qatar Qatar(+974)
Romania Romania(+40)
Serbia Serbia(+381)
Russia Russia(+7)
Rwanda Rwanda(+250)
Saudi Arabia Saudi Arabia(+966)
Solomon Islands Solomon Islands(+677)
Seychelles Seychelles(+248)
Sudan Sudan(+249)
Sweden Sweden(+46)
Singapore Singapore(+65)
Slovenia Slovenia(+386)
Slovakia Slovakia(+421)
Sierra Leone Sierra Leone(+232)
San Marino San Marino(+378)
Senegal Senegal(+221)
Somalia Somalia(+252)
Suriname Suriname(+597)
Sao Tome and Principe Sao Tome and Principe(+239)
El Salvador El Salvador(+503)
Syria Syria(+963)
Swaziland Swaziland(+268)
Turks and Caicos Islands Turks and Caicos Islands(+1 649)
Chad Chad(+235)
Togo Togo(+228)
Thailand Thailand(+66)
Tajikistan Tajikistan(+992)
Timor-Leste Timor-Leste(+670)
Turkmenistan Turkmenistan(+993)
Tunisia Tunisia(+216)
Tonga Tonga(+676)
Turkey Turkey(+90)
Trinidad and Tobago Trinidad and Tobago(+1 868)
Taiwan Taiwan(+886)
Tanzania Tanzania(+255)
Ukraine Ukraine(+380)
Uganda Uganda(+256)
United States United States(+1)
Uruguay Uruguay(+598)
Uzbekistan Uzbekistan(+998)
Saint Vincent and the Grenadines Saint Vincent and the Grenadines(+1 784)
Venezuela Venezuela(+58)
Virgin Islands, British Virgin Islands, British(+1 284)
Vietnam Vietnam(+84)
Vanuatu Vanuatu(+678)
Samoa Samoa(+685)
Yemen Yemen(+967)
South Africa South Africa(+27)
Zambia Zambia(+260)
Zimbabwe Zimbabwe(+263)
Enquiry *
Check out our Privacy Policy to learn more about how we handle your personal data.
* Required fields
decor banner Left

Others