We may earn an affiliate commission when you visit our partners.

STRIDE

Save
May 1, 2024 2 minute read

STRIDE is a threat modeling framework that helps organizations identify and mitigate security risks in their systems and applications. It is a structured approach that can be used to assess the security of a system or application, and to identify and prioritize the most important risks to address.

What is STRIDE?

STRIDE is an acronym that stands for:

  • Spoofing: Impersonating another user or system.
  • Tampering: Modifying data or code without authorization.
  • Repudiation: Denying responsibility for an action or event.
  • Information disclosure: Exposing sensitive information to unauthorized parties.
  • Denial of service: Preventing a user or system from accessing a resource.
  • Elevation of privilege: Gaining unauthorized access to higher-level privileges.

STRIDE can be used to assess the security of a system or application by identifying the potential threats that could exploit each of these vulnerabilities. Once the threats have been identified, they can be prioritized based on their likelihood and impact, and appropriate mitigation measures can be put in place.

Why learn STRIDE?

There are many reasons why someone might want to learn STRIDE. Some of the most common reasons include:

Share

Help others find this page about STRIDE: by sharing it with your friends and followers:

Reading list

We've selected five books that we think will supplement your learning. Use these to develop background knowledge, enrich your coursework, and gain a deeper understanding of the topics covered in STRIDE.
This classic book on threat modeling covers STRIDE and other methodologies. It is geared towards making threat modeling more accessible to developers by using entity relationship diagrams. Entities can include users, interfaces, components, and data stores and the relationships describe data flows or messages.
Covers threat modeling from the perspective of risk management. It deals with threat modeling in the system development lifecycle and integrates elements of security risk management.
Uses STRIDE to find and fix vulnerabilities. It describes threat modeling as a risk management process and is written for enterprise IT environments.
Aims to improve the quality of threat models. It covers common mistakes and misconceptions and emphasizes the use of automated tools.
Table of Contents
Our mission

OpenCourser helps millions of learners each year. People visit us to learn workspace skills, ace their exams, and nurture their curiosity.

Our extensive catalog contains over 50,000 courses and twice as many books. Browse by search, by topic, or even by career interests. We'll match you to the right resources quickly.

Find this site helpful? Tell a friend about us.

Affiliate disclosure

We're supported by our community of learners. When you purchase or subscribe to courses and programs or purchase books, we may earn a commission from our partners.

Your purchases help us maintain our catalog and keep our servers humming without ads.

Thank you for supporting OpenCourser.

© 2016 - 2025 OpenCourser